Optimizely Configured Commerce Session Hijacking Vulnerability
Vulnerability
A medium-severity session hijacking vulnerability has been identified in Optimizely Configured Commerce versions prior to 5.2.2408. The issue arises when session tokens are transmitted as URL parameters, exposing sensitive information about the authenticated session.
Impact
Exploitation of this vulnerability could lead to unauthorized access to an authenticated user's session, allowing an attacker to impersonate the user.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
7.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
