CVE-2025-25191

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
Configurations

Configuration 1 (hide)

cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*

History

10 Oct 2025, 20:11

Type Values Removed Values Added
Summary
  • (es) Group-Office es una herramienta de CRM y groupware empresarial. Esta vulnerabilidad de XSS almacenado existe cuando la entrada del usuario en el campo Nombre no se depura correctamente antes de almacenarse. Esta vulnerabilidad se solucionó en la versión 6.8.100.
CPE cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*
First Time Group-office
Group-office group Office
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda - () https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda - Patch
References () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf - () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf - Exploit, Vendor Advisory

06 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-06 19:15

Updated : 2025-10-10 20:11


NVD link : CVE-2025-25191

Mitre link : CVE-2025-25191

CVE.ORG link : CVE-2025-25191


JSON object : View

Products Affected

group-office

  • group_office
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')