MEDIUM🇵🇱 Wersja polska

CVE-2025-61950

CVSS 5.3v4.0pub. 2025-12-12upd. 2026-02-17

In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Groupsession

    APP
    Groupsession
    < 5.3.0< 5.3.2< 5.3.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-20874HIGH7.5same product

Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and ...

CVE-2025-53523MEDIUM4.8same product

W GroupSession Free w wersjach poniżej 5.3.0, GroupSession byCloud poniżej 5.3.3 oraz GroupSession ZION poniże...

CVE-2025-57883MEDIUM5.1same product

W GroupSession Free edition przed wersją 5.3.0, GroupSession byCloud przed wersją 5.3.3 i GroupSession ZION pr...

CVE-2025-54407MEDIUM5.1same product

W GroupSession Free (wersja poniżej 5.3.0), GroupSession byCloud (poniżej 5.3.3) i GroupSession ZION (poniżej ...

CVE-2025-58576MEDIUM5.1same product

W edycjach GroupSession Free przed ver5.3.0, GroupSession byCloud przed ver5.3.3 i GroupSession ZION przed ver...