CVE-2025-22387

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/01/2025
Last modified:
21/05/2025

Description

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:* 5.2.2408 (excluding)