Cross-site request forgery in Japan Total System products - CVE-2025-58576
Published: December 8, 2025
Vulnerability identifier: #VU119243
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-58576
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Affected software
GroupSession Free edition
GroupSession ZION
GroupSession byCloud
GroupSession ZION
GroupSession byCloud
How to mitigate CVE-2025-58576
Install updates from vendor's website.
GroupSession Free edition - update to 5.3.0
GroupSession ZION - update to 5.3.2
GroupSession byCloud - update to 5.3.3
GroupSession ZION - update to 5.3.2
GroupSession byCloud - update to 5.3.3