Reflected Cross-Site Scripting Vulnerability in Group-Office by Intermesh
CVE-2025-48993
What is CVE-2025-48993?
Group-Office, an enterprise customer relationship management and groupware tool, is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw allows attackers to execute a malicious JavaScript payload through the Look and Feel formatting fields, which are accessible to any user. The application does not properly sanitize input in these fields, thereby exposing users to potential XSS attacks. Fortunately, this issue has been addressed in versions 6.8.123 and 25.0.27. Users are advised to update to these versions to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
groupoffice < 6.8.123 < 6.8.123
groupoffice < 25.0.27 < 25.0.27
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
