PT-2025-50875 · Unknown · Groupsession Bycloud+2

Published

2025-12-12

·

Updated

2026-02-17

·

CVE-2025-61950

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GroupSession Free edition versions prior to 5.3.0 GroupSession byCloud versions prior to 5.3.3 GroupSession ZION versions prior to 5.3.2
Description A flaw exists in GroupSession where a Circular notice can be created with a non-editable memo field, but the authorization check is improperly implemented. A logged-in user may be able to alter the memo field with a crafted request.
Recommendations Update GroupSession Free edition to version 5.3.0 or later. Update GroupSession byCloud to version 5.3.3 or later. Update GroupSession ZION to version 5.3.2 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61950

Affected Products

Groupsession Free Edition
Groupsession Zion
Groupsession Bycloud