Cross-Site Request Forgery in GroupSession Products by GroupSession Inc.
CVE-2025-58576

5.1MEDIUM

What is CVE-2025-58576?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple versions of GroupSession products. Users who access malicious pages while authenticated may inadvertently trigger unintended actions within the application. This poses significant security risks, as it could compromise the integrity of user accounts and application workflows. It is crucial for users running versions prior to 5.3.0 for the Free edition, 5.3.3 for the byCloud edition, and 5.3.2 for ZION to update immediately to mitigate this risk.

Affected Version(s)

GroupSession byCloud prior to ver5.3.3

GroupSession Free edition prior to ver5.3.0

GroupSession ZION prior to ver5.3.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58576 : Cross-Site Request Forgery in GroupSession Products by GroupSession Inc.