漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CVE-2025-11699
Vulnerability Description
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nopCommerce 安全漏洞
Vulnerability Description
nopCommerce是nopCommerce公司的一套开源的通用电子商务平台。 nopCommerce 4.70之前版本和4.80.3版本存在安全漏洞,该漏洞源于注销或会话终止后未使会话cookie失效,可能导致会话劫持。
CVSS Information
N/A
Vulnerability Type
N/A