CVE-2025-22387

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*

History

21 May 2025, 17:05

Type Values Removed Values Added
CPE cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*
Summary
  • (es) Se descubrió un problema en Optimizely Configured Commerce antes de la versión 5.2.2408. Existe un problema de gravedad media en las solicitudes de recursos en las que el token de sesión se envía como un parámetro de URL. Esto expone información sobre la sesión autenticada, que se puede aprovechar para el secuestro de sesiones.
CWE NVD-CWE-Other
References () https://support.optimizely.com/hc/en-us/articles/32695551034893-Configured-Commerce-Security-Advisory-COM-2024-06 - () https://support.optimizely.com/hc/en-us/articles/32695551034893-Configured-Commerce-Security-Advisory-COM-2024-06 - Vendor Advisory
First Time Optimizely configured Commerce
Optimizely

06 Jan 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Jan 2025, 03:15

Type Values Removed Values Added
CWE CWE-598

04 Jan 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-04 02:15

Updated : 2025-05-21 17:05


NVD link : CVE-2025-22387

Mitre link : CVE-2025-22387

CVE.ORG link : CVE-2025-22387


JSON object : View

Products Affected

optimizely

  • configured_commerce
CWE
CWE-598

Use of GET Request Method With Sensitive Query Strings

NVD-CWE-Other