CVE-2023-46730: Group-Office Group Office

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api/upload.php endpoint. The /api/upload.php endpoint does not filter URLs which allows a malicious user to cause the server to make resource requests to untrusted domains. Note that protocols like file:// can also be used to access the server disk. The request result (on success) can then be retrieved using /api/download.php. This issue has been addressed in versions 6.8.15, 6.7.54, and 6.6.177. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Group-Office Group Office: from 6.3.1, before 6.6.177 (fixed in 6.6.177); from 6.7.0, before 6.7.54 (fixed in 6.7.54); from 6.8.0, before 6.8.15 (fixed in 6.8.15)

Published 2023-11-07. Last modified 2026-06-17.