Stored and Blind Cross-Site Scripting Vulnerability in Group-Office by Intermesh
CVE-2025-48992

5.2MEDIUM

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
16 June 2025

What is CVE-2025-48992?

Group-Office, a customer relationship management and groupware tool, is vulnerable to a stored and blind cross-site scripting vulnerability found in the Name Field of user profiles. Attackers are able to exploit this flaw by inserting a malicious JavaScript payload as their name. When this user is added to another user’s address book in the Synchronization features, the script executes, potentially leading to unauthorized actions and data exposure. This security issue has been addressed in versions 6.8.123 and 25.0.27, emphasizing the importance of keeping software updated to mitigate such vulnerabilities.

Affected Version(s)

groupoffice < 6.8.123 < 6.8.123

groupoffice < 25.0.27 < 25.0.27

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48992 : Stored and Blind Cross-Site Scripting Vulnerability in Group-Office by Intermesh