CVE-2025-22387
CVE-2025-22387
Título es
CVE-2025-22387
Sáb, 04/01/2025 – 02:15
Tipo
CWE-598
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-22387
Descripción en
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
04/01/2025
04/01/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off