PT-2024-20192 · Unknown · Group-Office

Tsutomu Aramaki

+1

·

Published

2024-02-01

·

Updated

2024-02-06

·

CVE-2024-23941

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Group Office versions prior to 6.6.182 Group Office versions prior to 6.7.64 Group Office versions prior to 6.8.31
Description A cross-site scripting issue exists, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
Recommendations For versions prior to 6.6.182, update to version 6.6.182 or later. For versions prior to 6.7.64, update to version 6.7.64 or later. For versions prior to 6.8.31, update to version 6.8.31 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-23941

Affected Products

Group-Office