NopCommerce Cookie Catastrophe: Session Hijacking Alert!
In the world of e-commerce, nopCommerce v4.10 and 4.80.3 seem to have a sweet tooth for cookies! Due to insufficient session cookie invalidation, even after saying goodbye, those cookies refuse to crumble, leaving the door wide open for session hijacking. Stay safe and keep your cookies in check!

Hot Take:
Who knew cookies could be so crumby? nopCommerce serves up a batch of session cookies that just won’t quit, leaving users vulnerable to a hack attack. It’s time to dunk these cookies once and for all!
Key Points:
- nopCommerce v4.10 and 4.80.3 suffer from session cookie invalidation issues.
- Session cookies remain valid even after logout, enabling unauthorized access.
- The vulnerability can lead to session hijacking and privilege escalation.
- Attackers can exploit this flaw through network interception or XSS.
- The flaw affects privileged endpoints, such as the admin panel.
Already a member? Log in here