Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.
CVSS
No CVSS.
References
Configurations
No configuration.
History
06 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-06 19:15
Updated : 2025-03-06 19:15
NVD link : CVE-2025-25191
Mitre link : CVE-2025-25191
CVE.ORG link : CVE-2025-25191
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')