PT-2026-3883 · Unknown · Group-Office

Jaroslaw-Wawiorko

·

Published

2026-01-21

·

Updated

2026-02-18

·

CVE-2026-23887

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Group-Office versions 6.8.148 and below Group-Office versions 25.0.1 through 25.0.79
Description Group-Office, an enterprise customer relationship management and groupware tool, stores unsanitized filenames in the database. This can lead to Stored Cross-Site Scripting (XSS) when users interact with these crafted filenames within the application. The impact is limited to the file-viewing context, potentially allowing interference with user sessions or unintended actions in the browser.
Recommendations Update Group-Office to version 6.8.149 or later. Update Group-Office to version 25.0.80 or later.

Exploit

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-23887
GHSA-3GJ5-GVVR-G6HP

Affected Products

Group-Office