Merijn Schering
11 exploits
Active since Nov 2023
Group-Office <6.8.123, 25.0.27 - XSS
CVSS 6.1
Group-Office <6.8.148 & 25.0.1-25.0.79 - XSS
CVSS 5.4
Group-Office < 6.8.150 - Authenticated Remote Code Execution via tmp_file Parameter
CVSS 8.8
Group-Office 6.3.1-6.6.176 - Server-Side Request Forgery via upload.php
CVSS 7.4
Group-Office < 6.8.29 - Stored Cross-Site Scripting via Filename Upload
CVSS 6.5
Group-Office - Stored Cross-Site Scripting in Name Field
CVSS 5.4
Group-Office <6.8.123, 25.0.27 - XSS
CVSS 4.8
Group-Office <6.8.123, 25.0.27 - XSS
CVSS 6.1
Group-Office <6.8.148 & 25.0.1-25.0.79 - XSS
CVSS 5.4
Group-Office <6.8.150, 25.0.82, 26.0.5 - RCE
CVSS 8.8
Group-Office 6.8.0-6.8.149 - Authenticated Server-Side Request Forgery via WOPI Service Discovery URL
CVSS 4.9