Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
History

Thu, 06 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Mar 2025 19:00:00 +0000

Type Values Removed Values Added
Description Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
Title Group-Office has a Stored XSS Vulnerability via user's name field
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-06T18:41:00.761Z

Updated: 2025-03-06T20:35:12.106Z

Reserved: 2025-02-03T19:30:53.399Z

Link: CVE-2025-25191

cve-icon Vulnrichment

Updated: 2025-03-06T20:35:07.860Z

cve-icon NVD

Status : Received

Published: 2025-03-06T19:15:27.113

Modified: 2025-03-06T19:15:27.113

Link: CVE-2025-25191

cve-icon Redhat

No data.