SQL Injection Vulnerability in GroupSession by Cloud
CVE-2025-62192
5.3MEDIUM
What is CVE-2025-62192?
An SQL Injection vulnerability has been identified in multiple versions of GroupSession, allowing authenticated users to potentially access or modify sensitive information stored in the database. This vulnerability underscores the importance of timely updates, as affected versions include the GroupSession Free edition before 5.3.0, GroupSession by Cloud before 5.3.3, and GroupSession ZION before 5.3.2. Administrators using these versions should apply the necessary patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
GroupSession byCloud prior to ver5.3.3
GroupSession Free edition prior to ver5.3.0
GroupSession ZION prior to ver5.3.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
