top of page
perceptive_background_267k.jpg

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injecti…

Published:

26 maart 2026 om 23:00:00

Alert date:

27 maart 2026 om 20:07:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage

Group-Office, an enterprise CRM and groupware tool, contains an authenticated SQL injection vulnerability in the JMAP Contact/query endpoint. The vulnerability affects versions prior to 6.8.158, 25.0.92, and 26.0.17. Any authenticated user with basic addressbook access can exploit this flaw to extract arbitrary data from the database, including active session tokens of other users. This enables complete account takeover of any user, including System Administrators, without requiring password knowledge. The vulnerability has been patched in the specified versions.

Technical details

Mitigation steps:

Affected products:

Group-Office

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page