GroupSession Free edition prior to ver5.3.0, GroupSession...
Moderate severity
Unreviewed
Published
Dec 12, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Dec 12, 2025
Published to the GitHub Advisory Database
Dec 12, 2025
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
References