PT-2025-48449 · Unknown · Nopcommerce
Beafn28
+1
·
Published
2025-12-01
·
Updated
2026-01-06
·
CVE-2025-11699
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
nopCommerce versions prior to 4.80.3
Description
The software does not invalidate session cookies after logout or session termination. This allows an attacker with a valid session cookie to access privileged endpoints, such as '/admin', even after the legitimate user has logged out, potentially enabling session hijacking. Approximately 40.8k instances are exposed. The issue allows attackers to reuse expired session cookies due to a logout flaw, potentially leading to account hijacking, including administrative access.
Recommendations
Versions prior to 4.80.3 should be updated to version 4.80.3 or later.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nopcommerce