Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the email_font_size setting directly into JavaScript without escaping. By combining these two issues, any low-privileged authenticated user can overwrite an administrator's email_font_size setting with a JavaScript payload and trigger stored XSS in the administrator's browser when the GroupOffice web client loads views/Extjs3/modulescripts.php. This vulnerability is fixed in 26.0.25, 25.0.100, and 6.8.165.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-639",
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45551.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "25.0.1"
},
{
"fixed": "25.0.1005"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "26.0.1"
},
{
"fixed": "26.0.25"
},
{
"introduced": "0"
},
{
"fixed": "6.8.165"
}
],
"source": "AFFECTED_FIELD"
}