Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2025-11699
Vulnerability Description
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nopCommerce 安全漏洞
Vulnerability Description
nopCommerce是nopCommerce公司的一套开源的通用电子商务平台。 nopCommerce 4.70之前版本和4.80.3版本存在安全漏洞,该漏洞源于注销或会话终止后未使会话cookie失效,可能导致会话劫持。
CVSS Information
N/A
Vulnerability Type
N/A