Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25452 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. |
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN72111431/ |
|
| https://www.group-office.com/ |
|
Wed, 24 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Group-office
Group-office group Office |
|
| CPEs | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Group-office
Group-office group Office |
Thu, 21 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intermesh
Intermesh group-office |
|
| Vendors & Products |
Intermesh
Intermesh group-office |
Thu, 21 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-08-21T15:47:02.814Z
Reserved: 2025-07-01T07:31:26.725Z
Link: CVE-2025-53504
Updated: 2025-08-21T15:46:58.721Z
Status : Analyzed
Published: 2025-08-21T05:15:32.037
Modified: 2025-09-24T00:14:41.750
Link: CVE-2025-53504
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:30:45Z
EUVD