PT-2025-50874 · Unknown · Groupsession Zion+2

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-58576

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GroupSession Free edition versions prior to 5.3.0 GroupSession byCloud versions prior to 5.3.3 GroupSession ZION versions prior to 5.3.2
Description A cross-site request forgery condition exists that could allow unintended operations to be performed if a user accesses a malicious page while logged in.
Recommendations Update GroupSession Free edition to version 5.3.0 or later. Update GroupSession byCloud to version 5.3.3 or later. Update GroupSession ZION to version 5.3.2 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-58576

Affected Products

Groupsession Free Edition
Groupsession Zion
Groupsession Bycloud