CVE-2025-48992
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/06/2025
Last modified:
04/09/2025
Description
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists in the Name Field of the user profile. A malicious attacker can change their name to a javascript payload, which is executed when a user adds the malicious user to their Synchronization > Address books. This issue has been patched in versions 6.8.123 and 25.0.27.
Impact
Base Score 4.0
5.20
Severity 4.0
MEDIUM
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:* | 6.8.123 (excluding) | |
cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:* | 25.0.1 (including) | 25.0.27 (excluding) |
To consult the complete list of CPE names with products and versions, see this page