nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a
a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above 4.70 that is not 4.80.3 fixes the vulnerability.
References
| Link | Resource |
|---|---|
| https://github.com/nopSolutions/nopCommerce/issues/7044 | Issue Tracking |
| https://seclists.org/fulldisclosure/2025/Aug/14 | Mailing List Third Party Advisory |
| https://www.nopcommerce.com/en/release-notes?srsltid=AfmBOoravPKjN19pm_XZbXZ7GvPhkt8cxlK6794BJRZlY5RxJU_yNoTT | Release Notes |
| https://www.kb.cert.org/vuls/id/633103 | Third Party Advisory Patch |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-01 16:15
Updated : 2025-12-19 17:02
NVD link : CVE-2025-11699
Mitre link : CVE-2025-11699
CVE.ORG link : CVE-2025-11699
JSON object : View
Products Affected
nopcommerce
- nopcommerce
CWE
CWE-613
Insufficient Session Expiration
