CVE-2025-48366 - CVE House
Back to Database
Status published Medium CVE-2025-48366

GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions

Vulnerability Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a stored and blind XSS vulnerability exists in the Phone Number field of the user profile within the GroupOffice application. This allows a malicious actor to inject persistent JavaScript payloads, which are triggered in the context of another user when they view the Address Book. Successful exploitation enables actions such as forced redirects, unauthorized fetch requests, or other arbitrary JavaScript execution without user interaction. Versions 6.8.119 and 25.0.20 contain a fix for the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48366

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

groupoffice
Vulnerable Versions:
< 6.8.119, < 25.0.20

Timeline

Official Publish: May 22nd, 2025
Last Modified: May 22nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)