Логотип exploitDog
bind:CVE-2025-22387
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-22387

Количество 2

Количество 2

nvd логотип

CVE-2025-22387

около 1 года назад

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p626-9v99-xc4x

около 1 года назад

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-22387

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-p626-9v99-xc4x

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу