Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvxm-fhfx-8g6r

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.4

Описание

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 месяцев назад

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79