An issue was discovered in Optimizely Configured Commerce...
High severity
Unreviewed
Published
Jan 4, 2025
to the GitHub Advisory Database
•
Updated Jan 6, 2025
Description
Published by the National Vulnerability Database
Jan 4, 2025
Published to the GitHub Advisory Database
Jan 4, 2025
Last updated
Jan 6, 2025
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
References