Stored and Blind XSS Vulnerability in Group-Office CRM Tool
CVE-2025-48366
What is CVE-2025-48366?
A vulnerability exists in the Group-Office application that allows attackers to exploit the Phone Number field in user profiles. This stored and blind XSS issue, present in versions before 6.8.119 and 25.0.20, permits a malicious actor to inject persistent JavaScript payloads. When an unsuspecting user views their Address Book, these payloads trigger in their context, enabling actions such as forced redirects and unauthorized requests. Updating to the fixed versions is essential to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
groupoffice < 6.8.119 < 6.8.119
groupoffice < 25.0.20 < 25.0.20
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
