CVE-2025-25191

Source
https://cve.org/CVERecord?id=CVE-2025-25191
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25191.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-25191
Aliases
  • GHSA-j7p3-v652-p3gf
Published
2025-03-06T18:41:00.761Z
Modified
2026-07-15T01:49:09.986815434Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Group-Office has a Stored XSS Vulnerability via user's name field
Details

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25191.json"
}
References

Affected packages

Git / github.com/intermesh/groupoffice

Affected ranges

Type
GIT
Repo
https://github.com/intermesh/groupoffice
Events
Database specific
{
    "cpe": "cpe:2.3:a:group-office:group_office:6.8.99:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.8.99"
        },
        {
            "last_affected": "6.8.99"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

6.*
6.8.99

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25191.json"