Cross-Site Scripting Vulnerability in Group-Office by Intermesh BV
CVE-2025-53504
What is CVE-2025-53504?
The applications provided by Intermesh BV, specifically Group-Office, are susceptible to a cross-site scripting vulnerability that affects versions before 6.8.119 and 25.0.20. If exploited, attackers can inject arbitrary scripts into user web sessions, potentially allowing unauthorized actions to be executed in the context of legitimate users. This vulnerability poses significant risks to user data and privacy, making it imperative for users of affected versions to apply available updates or security patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Group-Office prior to 6.8.119
Group-Office prior to 25.0.20
References
CVSS V4
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
