ZeroHour

CVE-2025-22386

CVSS 3.1
7.3 high
EPSS
<1%p21
Published
()
Modified
Description

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.

Vendors
optimizely
Products
configured commerce
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.