Session Token Vulnerability in PILOS by THM Health
CVE-2025-62781

5MEDIUM

Key Information:

Vendor

Thm-health

Status
Vendor
CVE Published:
27 October 2025

What is CVE-2025-62781?

PILOS, a frontend for BigBlueButton, presents a session token management flaw where users can change their account password while logged in. Although the password change terminates all other active sessions, the current session’s token remains valid and is not refreshed. If an attacker has previously gained access to this session token through a different vulnerability, they can continue to maintain their unauthorized access even after the legitimate user has updated their password. This flaw was addressed in version 4.8.0.

Affected Version(s)

PILOS < 4.8.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.