Stored and Blind XSS Vulnerability in Group-Office CRM Tool
CVE-2025-48366
6.9MEDIUM
What is CVE-2025-48366?
A vulnerability exists in the Group-Office application that allows attackers to exploit the Phone Number field in user profiles. This stored and blind XSS issue, present in versions before 6.8.119 and 25.0.20, permits a malicious actor to inject persistent JavaScript payloads. When an unsuspecting user views their Address Book, these payloads trigger in their context, enabling actions such as forced redirects and unauthorized requests. Updating to the fixed versions is essential to mitigate this security risk.
Affected Version(s)
groupoffice < 6.8.119 < 6.8.119
groupoffice < 25.0.20 < 25.0.20
