Session Token Vulnerability in PILOS by THM Health
CVE-2025-62781
5MEDIUM
What is CVE-2025-62781?
PILOS, a frontend for BigBlueButton, presents a session token management flaw where users can change their account password while logged in. Although the password change terminates all other active sessions, the current session’s token remains valid and is not refreshed. If an attacker has previously gained access to this session token through a different vulnerability, they can continue to maintain their unauthorized access even after the legitimate user has updated their password. This flaw was addressed in version 4.8.0.
Affected Version(s)
PILOS < 4.8.0
