Stored Cross-Site Scripting in GroupSession by GroupSession
CVE-2025-66284
What is CVE-2025-66284?
Stored cross-site scripting vulnerabilities in GroupSession can allow attackers to embed malicious scripts in web pages. When a logged-in user creates a harmful URL or page, the arbitrary script could execute in the web browser of an unsuspecting user who accesses it. This potentially leads to unauthorized access to sensitive information and impacts overall security. It is critical for users of the affected versions to update promptly to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GroupSession byCloud prior to ver5.7.1
GroupSession Free edition prior to ver5.7.1
GroupSession ZION prior to ver5.7.1
References
CVSS V4
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
