Session Token Exposure in Optimizely Configured Commerce
CVE-2025-22387

Currently unrated

Key Information:

Vendor

Optimizely

Vendor
CVE Published:
4 January 2025

What is CVE-2025-22387?

A vulnerability has been identified in Optimizely Configured Commerce prior to version 5.2.2408, where the session token is transmitted as a URL parameter during resource requests. This implementation flaw allows for the potential exposure of sensitive authenticated session information. Attackers can exploit this vulnerability to perform session hijacking, compromising user accounts and accessing sensitive data. It is critical for users and administrators to ensure they update to secure versions and follow best practices in securing session tokens.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.