Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 23 Jan 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:groupsession:groupsession:*:*:*:*:bycloud:*:*:* cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:* cpe:2.3:a:groupsession:groupsession:*:*:*:*:zion:*:*:* |
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Groupsession
Groupsession groupsession Groupsession groupsession Bycloud Groupsession groupsession Zion |
|
| Vendors & Products |
Groupsession
Groupsession groupsession Groupsession groupsession Bycloud Groupsession groupsession Zion |
Fri, 12 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended operations may be performed. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-12-12T20:23:14.206Z
Reserved: 2025-11-27T05:42:04.077Z
Link: CVE-2025-58576
Updated: 2025-12-12T20:23:09.530Z
Status : Analyzed
Published: 2025-12-12T05:16:07.407
Modified: 2026-01-23T02:22:17.410
Link: CVE-2025-58576
No data.
OpenCVE Enrichment
Updated: 2025-12-12T08:47:58Z