CVE Vulnerabilities

CVE-2025-64781

Initialization of a Resource with an Insecure Default

Published: Dec 12, 2025 | Modified: Dec 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, External page display restriction is set to Do not limit in the initial configuration. With this configuration, the user may be redirected to an arbitrary website when accessing a specially crafted URL.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

References