Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.
No PoCs from references.
- https://github.com/brainkok/CVE-2023-25292
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/tucommenceapousser/CVE-2023-25292