PT-2025-50878 · Unknown · Groupsession

Published

2025-12-12

·

Updated

2026-02-17

·

CVE-2025-64781

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GroupSession versions prior to 5.7.1
Description The software’s initial configuration may have the "External page display restriction" set to "Do not limit". This configuration allows a user to be redirected to an arbitrary website when accessing a specially crafted URL.
Recommendations Update to version 5.7.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64781

Affected Products

Groupsession