Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgx3-j7fm-pjm3

Опубликовано: 01 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.

nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.

EPSS

Процентиль: 10%
0.00036
Низкий

7.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.

EPSS

Процентиль: 10%
0.00036
Низкий

7.1 High

CVSS3

Дефекты

CWE-613