PT-2025-25592 · Unknown · Group-Office
Kh0Kamoni
·
Published
2025-06-16
·
Updated
2025-06-17
·
CVE-2025-48992
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Group-Office versions prior to 6.8.123
Group-Office versions prior to 25.0.27
Description
A stored and blind cross-site scripting (XSS) issue exists in the Name Field of the user profile. An attacker can change their name to a javascript payload, which is executed when a user adds the malicious user to their Synchronization > Address books.
Recommendations
For versions prior to 6.8.123, update to version 6.8.123 or later.
For versions prior to 25.0.27, update to version 25.0.27 or later.
As a temporary workaround, consider restricting the ability to add users to the Synchronization > Address books until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Group-Office