Cross-Site Scripting Vulnerability in Group-Office by Intermesh BV
CVE-2025-53504
4.8MEDIUM
What is CVE-2025-53504?
The applications provided by Intermesh BV, specifically Group-Office, are susceptible to a cross-site scripting vulnerability that affects versions before 6.8.119 and 25.0.20. If exploited, attackers can inject arbitrary scripts into user web sessions, potentially allowing unauthorized actions to be executed in the context of legitimate users. This vulnerability poses significant risks to user data and privacy, making it imperative for users of affected versions to apply available updates or security patches.
Affected Version(s)
Group-Office prior to 6.8.119
Group-Office prior to 25.0.20
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
