PT-2026-3883 · Unknown · Group-Office
Jaroslaw-Wawiorko
·
Published
2026-01-21
·
Updated
2026-02-18
·
CVE-2026-23887
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Group-Office versions 6.8.148 and below
Group-Office versions 25.0.1 through 25.0.79
Description
Group-Office, an enterprise customer relationship management and groupware tool, stores unsanitized filenames in the database. This can lead to Stored Cross-Site Scripting (XSS) when users interact with these crafted filenames within the application. The impact is limited to the file-viewing context, potentially allowing interference with user sessions or unintended actions in the browser.
Recommendations
Update Group-Office to version 6.8.149 or later.
Update Group-Office to version 25.0.80 or later.
Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Group-Office