GroupSession is a web-based HR management software used by some organizations. This vulnerability allows attackers to execute arbitrary scripts on users' web browsers when accessing crafted pages or URLs, potentially leading to unauthorized access to user data and system configuration.