PT-2025-25592 · Unknown · Group-Office

Kh0Kamoni

·

Published

2025-06-16

·

Updated

2025-06-17

·

CVE-2025-48992

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Group-Office versions prior to 6.8.123 Group-Office versions prior to 25.0.27
Description A stored and blind cross-site scripting (XSS) issue exists in the Name Field of the user profile. An attacker can change their name to a javascript payload, which is executed when a user adds the malicious user to their Synchronization > Address books.
Recommendations For versions prior to 6.8.123, update to version 6.8.123 or later. For versions prior to 25.0.27, update to version 25.0.27 or later. As a temporary workaround, consider restricting the ability to add users to the Synchronization > Address books until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-48992
GHSA-J35G-Q5MC-JWGP

Affected Products

Group-Office