Reflected Cross-Site Scripting Vulnerability in Group-Office by Intermesh
CVE-2025-48993
5.3MEDIUM
What is CVE-2025-48993?
Group-Office, an enterprise customer relationship management and groupware tool, is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw allows attackers to execute a malicious JavaScript payload through the Look and Feel formatting fields, which are accessible to any user. The application does not properly sanitize input in these fields, thereby exposing users to potential XSS attacks. Fortunately, this issue has been addressed in versions 6.8.123 and 25.0.27. Users are advised to update to these versions to mitigate risks.
Affected Version(s)
groupoffice < 6.8.123 < 6.8.123
groupoffice < 25.0.27 < 25.0.27