← Vulnerability feed

Vulnerability record · CVE-2024-23941 · published 1 February 2024

CVE-2024-23941: Group-office group office cross-site scripting vulnerability

Group Office · Group Office

Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

5.4 CVSS 3.1 Medium EPSS 0.62% · top 52.5% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23941 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25512Group-office group office os command injection vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …EPSS 3.5%9.4CVE-2026-25134Group-office group office argument injection vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController e…EPSS 0.85%8.8CVE-2025-63406Group-office group office command injection vulnerabilityAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and…EPSS 0.74%8.8CVE-2023-46730Group-office group office server-side request forgery (ssrf) vulnerabilityGroup-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api…EPSS 0.60%8.2CVE-2026-25511Group-office group office server-side request forgery (ssrf) vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated u…EPSS 0.43%6.9CVE-2025-25191Group-office group office cross-site scripting vulnerabilityGroup-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitiz…EPSS 0.28%6.1CVE-2023-25292Group-office group office cross-site scripting vulnerabilityReflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive i…EPSS 0.59%6.1CVE-2020-35419Group-office group office cross-site scripting vulnerabilityCross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.EPSS 0.67%

Source: NIST National Vulnerability Database (record CVE-2024-23941), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.