Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel formatting fields. Any user can update their Look and Feel Formatting input fields, but the web application does not sanitize their input. This could result in a reflected cross-site scripting (XSS) attack. This issue has been patched in versions 6.8.123 and 25.0.27.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel formatting fields. Any user can update their Look and Feel Formatting input fields, but the web application does not sanitize their input. This could result in a reflected cross-site scripting (XSS) attack. This issue has been patched in versions 6.8.123 and 25.0.27. | |
Title | Group-Office vulnerable to reflected XSS via Look and Feel Formatting input | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-17T00:43:35.194Z
Updated: 2025-06-17T13:45:06.357Z
Reserved: 2025-05-29T16:34:07.174Z
Link: CVE-2025-48993

Updated: 2025-06-17T13:45:00.706Z

Status : Awaiting Analysis
Published: 2025-06-17T01:15:22.360
Modified: 2025-06-17T20:50:23.507
Link: CVE-2025-48993

No data.