CVE-2025-25191

G

roup-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.

Configurations

Configuration 1 (hide)

cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*

History

10 Oct 2025, 20:11

Type Values Removed Values Added
First Time Group-office group Office
Group-office
References () https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda - () https://github.com/Intermesh/groupoffice/commit/c5c83e19a5cdf93b0e758726c97597861f1d6eda - Patch
References () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf - () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-j7p3-v652-p3gf - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*

06 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-06 19:15

Updated : 2025-10-10 20:11


NVD link : CVE-2025-25191

Mitre link : CVE-2025-25191

CVE.ORG link : CVE-2025-25191


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')