Cross-Site Scripting Vulnerability in Group-Office by Intermesh BV
CVE-2025-53504

4.8MEDIUM

Key Information:

Vendor
CVE Published:
21 August 2025

What is CVE-2025-53504?

The applications provided by Intermesh BV, specifically Group-Office, are susceptible to a cross-site scripting vulnerability that affects versions before 6.8.119 and 25.0.20. If exploited, attackers can inject arbitrary scripts into user web sessions, potentially allowing unauthorized actions to be executed in the context of legitimate users. This vulnerability poses significant risks to user data and privacy, making it imperative for users of affected versions to apply available updates or security patches.

Affected Version(s)

Group-Office prior to 6.8.119

Group-Office prior to 25.0.20

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.