๐Ÿ” CVE Alert

CVE-2026-45551

UNKNOWN 0.0

Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the email_font_size setting directly into JavaScript without escaping. By combining these two issues, any low-privileged authenticated user can overwrite an administrator's email_font_size setting with a JavaScript payload and trigger stored XSS in the administrator's browser when the GroupOffice web client loads views/Extjs3/modulescripts.php. This vulnerability is fixed in 26.0.25, 25.0.100, and 6.8.165.

CWE CWE-79 CWE-639
Vendor intermesh
Product groupoffice
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for intermesh groupoffice

Be the first to know when new unknown vulnerabilities affecting intermesh groupoffice are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Intermesh / groupoffice
>= 26.0.1, < 26.0.25 >= 25.0.1, < 25.0.1005 < 6.8.165

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Intermesh/groupoffice/security/advisories/GHSA-9w92-p32g-g99p