CVE-2025-22386 - Optimizely Configured Commerce Session Token Tampering
CVE ID : CVE-2025-22386 Published : Jan. 4, 2025, 2:15 a.m. | 44 minutes ago Description : An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Published : Jan. 4, 2025, 2:15 a.m. | 44 minutes ago
Description : An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...