Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95x3-5ffc-v69j

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.4

Описание

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 месяцев назад

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79