Cross-Site Request Forgery in GroupSession Products by GroupSession Inc.
CVE-2025-58576
5.1MEDIUM
What is CVE-2025-58576?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple versions of GroupSession products. Users who access malicious pages while authenticated may inadvertently trigger unintended actions within the application. This poses significant security risks, as it could compromise the integrity of user accounts and application workflows. It is crucial for users running versions prior to 5.3.0 for the Free edition, 5.3.3 for the byCloud edition, and 5.3.2 for ZION to update immediately to mitigate this risk.
Affected Version(s)
GroupSession byCloud prior to ver5.3.3
GroupSession Free edition prior to ver5.3.0
GroupSession ZION prior to ver5.3.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
