Open Redirect Vulnerability in GroupSession by GroupSession and byCloud
CVE-2021-20789

6.1MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2021

What is CVE-2021-20789?

An open redirect vulnerability exists in the GroupSession platform that can be exploited by remote attackers. This flaw affects the Free edition, byCloud, and ZION versions of GroupSession, allowing attackers to craft malicious URLs. Upon exploitation, users can be redirected to arbitrary websites, creating opportunities for phishing attacks and potentially compromising sensitive information. Keeping your GroupSession software updated is crucial to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GroupSession GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.