Stored and Blind Cross-Site Scripting Vulnerability in Group-Office by Intermesh
CVE-2025-48992
5.2MEDIUM
What is CVE-2025-48992?
Group-Office, a customer relationship management and groupware tool, is vulnerable to a stored and blind cross-site scripting vulnerability found in the Name Field of user profiles. Attackers are able to exploit this flaw by inserting a malicious JavaScript payload as their name. When this user is added to another user’s address book in the Synchronization features, the script executes, potentially leading to unauthorized actions and data exposure. This security issue has been addressed in versions 6.8.123 and 25.0.27, emphasizing the importance of keeping software updated to mitigate such vulnerabilities.
Affected Version(s)
groupoffice < 6.8.123 < 6.8.123
groupoffice < 25.0.27 < 25.0.27