Session Token Exposure in Optimizely Configured Commerce
CVE-2025-22387
Currently unrated
What is CVE-2025-22387?
A vulnerability has been identified in Optimizely Configured Commerce prior to version 5.2.2408, where the session token is transmitted as a URL parameter during resource requests. This implementation flaw allows for the potential exposure of sensitive authenticated session information. Attackers can exploit this vulnerability to perform session hijacking, compromising user accounts and accessing sensitive data. It is critical for users and administrators to ensure they update to secure versions and follow best practices in securing session tokens.