CVE-2021-20875
CVE-2021-20875
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.8%KEV nãoPoC —Patch —
Lifecycle
24 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.
Affected products
Japan Total System Co.,Ltd. · GroupSession Free edition, GroupSession byCloud, GroupSession ZIONWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →