CVE-2025-25191

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
Configurations

Configuration 1 (hide)

cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-06 19:15

Updated : 2025-10-10 20:11


NVD link : CVE-2025-25191

Mitre link : CVE-2025-25191

CVE.ORG link : CVE-2025-25191


JSON object : View

Products Affected

group-office

  • group_office
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')