Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-25292

Description

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.

POC

Reference

No PoCs from references.

Github

- https://github.com/brainkok/CVE-2023-25292

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/tucommenceapousser/CVE-2023-25292