Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Group-Office has stored XSS vulnerability via unsanitized filenames
Vulnerability Description
Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the application stores unsanitized filenames in the database, which can lead to Stored Cross-Site Scripting (XSS). Users who interact with these specially crafted file names within the Group-Office application are affected. While the scope is limited to the file-viewing context, it could still be used to interfere with user sessions or perform unintended actions in the browser. This issue is fixed in versions 6.8.149 and 25.0.80.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Group Office 跨站脚本漏洞
Vulnerability Description
Group Office是荷兰Group Office公司的一款模块化的办公套件。 Group Office 6.8.148及之前版本和25.0.1版本至25.0.79版本存在跨站脚本漏洞,该漏洞源于应用程序在数据库中存储未清理的文件名,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A