Beveiligingsadvies

CVE-2025-61987

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-12 05:02:22
Laatst bijgewerkt 2025-12-12 20:22:14
Toegewezen door jpcert
CVSS-score 6.9
Status PUBLISHED

Beschrijving

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.