Home
MEDIUM: 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NMEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N prior to ver5.3.0
affected
prior to ver5.3.3
affected
prior to ver5.3.2
affected
Description
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
Problem types
Missing origin validation in WebSockets
Product status
References
groupsession.jp/info/info-news/security20251208
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.