Japan Total System GroupSession
cpe:2.3:a:groupsession:groupsession:*:*:*:*:*:*:*
- < 5.3.0
- < 5.3.3
- < 5.3.2
- < 5.7.1
A vulnerability exists in GroupSession Free edition prior to 5.3.0, GroupSession byCloud prior to 5.3.3, and GroupSession ZION prior to 5.3.2, where WebSocket connections lack proper origin validation. This flaw can lead to the exposure of chat information sent to users who access a crafted page.
Exploitation of this vulnerability could result in the unauthorized exposure of chat information to users.
Users are advised to update to the latest version of GroupSession. The latest version can be downloaded from the GroupSession website. Note that GroupSession byCloud has already addressed this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.