CVE-2025-48369 is a persistent Cross-Site Scripting (XSS) vulnerability affecting Group-Office versions prior to 6.8.119 and 25.0.20. Attackers can exploit this by uploading a file with a crafted filename containing an XSS payload within the tasks comment functionality. The vulnerability has a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction, with potential for limited confidentiality and integrity impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.8.199CPE matchmatch criteria | cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:* | ||
>= 25.0.1, < 25.0.20CPE matchmatch criteria | cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.