PT-2025-50872 · Unknown · Groupsession Bycloud+2

Published

2025-12-12

·

Updated

2026-02-17

·

CVE-2025-54407

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GroupSession Free edition versions prior to 5.3.0 GroupSession byCloud versions prior to 5.3.3 GroupSession ZION versions prior to 5.3.2
Description A stored cross-site scripting issue exists. If a user accesses a specially crafted page or URL, an arbitrary script may be executed in the user's web browser.
Recommendations Update GroupSession Free edition to version 5.3.0 or later. Update GroupSession byCloud to version 5.3.3 or later. Update GroupSession ZION to version 5.3.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54407

Affected Products

Groupsession Free Edition
Groupsession Zion
Groupsession Bycloud