Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 23 Jan 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:groupsession:groupsession:*:*:*:*:bycloud:*:*:* cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:* cpe:2.3:a:groupsession:groupsession:*:*:*:*:zion:*:*:* |
Fri, 12 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Groupsession
Groupsession groupsession Groupsession groupsession Bycloud Groupsession groupsession Zion |
|
| Vendors & Products |
Groupsession
Groupsession groupsession Groupsession groupsession Bycloud Groupsession groupsession Zion |
Fri, 12 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-12-12T18:45:37.543Z
Reserved: 2025-11-27T05:42:12.333Z
Link: CVE-2025-57883
Updated: 2025-12-12T18:45:32.562Z
Status : Analyzed
Published: 2025-12-12T05:16:07.180
Modified: 2026-01-23T02:29:27.067
Link: CVE-2025-57883
No data.
OpenCVE Enrichment
Updated: 2025-12-12T08:48:20Z