Authorization Flaw in GroupSession Affects Memo Field Editing
CVE-2025-61950
5.3MEDIUM
What is CVE-2025-61950?
In GroupSession, a serious issue has been identified where the authorization check for creating Circular notices with a non-editable memo field is poorly implemented. As a result, a logged-in user can exploit this vulnerability to modify the memo field, which should otherwise remain unalterable. This vulnerability affects multiple versions of GroupSession, including the Free edition prior to version 5.3.0, GroupSession byCloud prior to version 5.3.3, and GroupSession ZION before version 5.3.2. It is crucial for users to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
GroupSession byCloud prior to ver5.3.3
GroupSession Free edition prior to ver5.3.0
GroupSession ZION prior to ver5.3.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
