CVE-2017-2166: Groupsession
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected products
- Groupsession Groupsession: up to and including 4.7.0
Published 2018-01-26. Last modified 2026-06-17.