Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
References
| Link | Resource |
|---|---|
| https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda | Patch |
| https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf | Exploit Vendor Advisory |
Configurations
History
10 Oct 2025, 20:11
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:* | |
| First Time |
Group-office
Group-office group Office |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda - Patch | |
| References | () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf - Exploit, Vendor Advisory |
06 Mar 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-03-06 19:15
Updated : 2025-10-10 20:11
NVD link : CVE-2025-25191
Mitre link : CVE-2025-25191
CVE.ORG link : CVE-2025-25191
JSON object : View
Products Affected
group-office
- group_office
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
