GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
History

Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Groupsession
Groupsession groupsession
Groupsession groupsession Bycloud
Groupsession groupsession Zion
Vendors & Products Groupsession
Groupsession groupsession
Groupsession groupsession Bycloud
Groupsession groupsession Zion

Fri, 12 Dec 2025 05:15:00 +0000

Type Values Removed Values Added
Description GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
Weaknesses CWE-1385
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-12-12T05:02:22.443Z

Updated: 2025-12-12T20:22:14.823Z

Reserved: 2025-11-27T05:42:08.569Z

Link: CVE-2025-61987

cve-icon Vulnrichment

Updated: 2025-12-12T20:22:09.105Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-12T05:16:07.763

Modified: 2025-12-12T15:17:31.973

Link: CVE-2025-61987

cve-icon Redhat

No data.