PT-2025-48449 · Unknown · Nopcommerce

Beafn28

+1

·

Published

2025-12-01

·

Updated

2026-01-06

·

CVE-2025-11699

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions nopCommerce versions prior to 4.80.3
Description The software does not invalidate session cookies after logout or session termination. This allows an attacker with a valid session cookie to access privileged endpoints, such as '/admin', even after the legitimate user has logged out, potentially enabling session hijacking. Approximately 40.8k instances are exposed. The issue allows attackers to reuse expired session cookies due to a logout flaw, potentially leading to account hijacking, including administrative access.
Recommendations Versions prior to 4.80.3 should be updated to version 4.80.3 or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11699

Affected Products

Nopcommerce