PT-2025-9991 · Unknown · Group-Office

0Xadik

·

Published

2025-03-06

·

Updated

2025-10-10

·

CVE-2025-25191

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Group-Office versions prior to 6.8.100
Description A Stored XSS issue exists due to improper sanitization of user input in the Name field. This allows for the storage of malicious scripts, which can be executed when the stored data is retrieved.
Recommendations For versions prior to 6.8.100, update to version 6.8.100 to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25191
GHSA-J7P3-V652-P3GF

Affected Products

Group-Office