Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-12-12
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-12-12
Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended operations may be performed.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-12-12
In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-12-12
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-12-12
Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-12
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
CVSS Score
3.7
EPSS Score
0.0
Published
2025-12-12
The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
CVSS Score
6.7
EPSS Score
0.0
Published
2025-12-12
Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3.
CVSS Score
6.7
EPSS Score
0.0
Published
2025-12-12
The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability
CVSS Score
6.7
EPSS Score
0.0
Published
2025-12-12


Contact Us

Shodan ® - All rights reserved