Stored and Blind XSS Vulnerability in Group-Office CRM Tool
CVE-2025-48366

6.9MEDIUM

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
22 May 2025

What is CVE-2025-48366?

A vulnerability exists in the Group-Office application that allows attackers to exploit the Phone Number field in user profiles. This stored and blind XSS issue, present in versions before 6.8.119 and 25.0.20, permits a malicious actor to inject persistent JavaScript payloads. When an unsuspecting user views their Address Book, these payloads trigger in their context, enabling actions such as forced redirects and unauthorized requests. Updating to the fixed versions is essential to mitigate this security risk.

Affected Version(s)

groupoffice < 6.8.119 < 6.8.119

groupoffice < 25.0.20 < 25.0.20

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.