Stored and Blind XSS Vulnerability in Group-Office CRM Tool
CVE-2025-48366

6.9MEDIUM

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
22 May 2025

What is CVE-2025-48366?

A vulnerability exists in the Group-Office application that allows attackers to exploit the Phone Number field in user profiles. This stored and blind XSS issue, present in versions before 6.8.119 and 25.0.20, permits a malicious actor to inject persistent JavaScript payloads. When an unsuspecting user views their Address Book, these payloads trigger in their context, enabling actions such as forced redirects and unauthorized requests. Updating to the fixed versions is essential to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

groupoffice < 6.8.119 < 6.8.119

groupoffice < 25.0.20 < 25.0.20

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.