Reflected Cross-Site Scripting Vulnerability in Group-Office by Intermesh
CVE-2025-48993

5.3MEDIUM

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
17 June 2025

What is CVE-2025-48993?

Group-Office, an enterprise customer relationship management and groupware tool, is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw allows attackers to execute a malicious JavaScript payload through the Look and Feel formatting fields, which are accessible to any user. The application does not properly sanitize input in these fields, thereby exposing users to potential XSS attacks. Fortunately, this issue has been addressed in versions 6.8.123 and 25.0.27. Users are advised to update to these versions to mitigate risks.

Affected Version(s)

groupoffice < 6.8.123 < 6.8.123

groupoffice < 25.0.27 < 25.0.27

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48993 : Reflected Cross-Site Scripting Vulnerability in Group-Office by Intermesh