VYPR

Group Office Groupware

by Intermesh

Source repositories

CVEs (3)

  • CVE-2010-3428Sep 16, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.

  • CVE-2024-22418MedJan 18, 2024
    risk 0.00cvss 6.5epss 0.00

    Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group Office. It allows an attacker to execute arbitrary JavaScript code by embedding it within a file's name. For instance,…

  • CVE-2007-2720May 16, 2007
    risk 0.00cvss epss 0.01

    Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.