CVE-2024-23941: Group-Office Group Office
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
Affected products
- Group-Office Group Office: before 6.6.182 (fixed in 6.6.182); from 6.7.0, before 6.7.64 (fixed in 6.7.64); from 6.8.0, before 6.8.31 (fixed in 6.8.31)
Published 2024-02-01. Last modified 2026-06-17.