CVE-2025-61950EPSS p7.8%
CVE-2025-61950CVE-2025-61950
groupsession / groupsession
Description
In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.19% probability of exploitation · percentile 7.8% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |