Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

nopCommerce Flaw Lets Attackers Access Accounts Using Captured Cookies

Security researchers have uncovered a serious vulnerability in nopCommerce, a popular open-source ecommerce platform used by major companies, including Microsoft, Volvo, and BMW. The flaw allows attackers to hijack user accounts by exploiting captured…

Security researchers have uncovered a serious vulnerability in nopCommerce, a popular open-source ecommerce platform used by major companies, including Microsoft, Volvo, and BMW. The flaw allows attackers to hijack user accounts by exploiting captured session cookies, even after legitimate users have logged out. FieldDetailsCVE IDCVE-2025-11699Vulnerability TitleInsufficient Session Cookie InvalidationPlatformnopCommerce (ASP.NET Core)SeverityHigh The Vulnerability Explained The vulnerability, tracked as CVE-2025-11699, stems from insufficient invalidation of session cookies in nopCommerce’s login system. When users log out, the platform fails to correctly invalidate their session cookies, leaving them vulnerable to abuse. An attacker who obtains a valid session cookie can use it to access restricted areas, including administrative endpoints, long after the original user has logged out. Session hijacking through cookie theft is not a new threat, but it remains highly effective. Attackers typically obtain cookies through cross-site scripting attacks (XSS), network interception, or by compromising a user’s device. Once captured, these cookies become valuable commodities sold on underground forums to other cybercriminals. According to Carnegie Mellon University, the vulnerability affects nopCommerce versions 4.70 and earlier, as well as 4.80.3. The platform serves as the backbone for numerous online stores worldwide and uses ASP.NET Core and MS SQL Server. Its integration with shipping APIs and content delivery networks makes it a critical piece of infrastructure for many businesses. The discovery of this flaw is particularly concerning because it mirrors CVE-2019-7215. This similar vulnerability exposed the same weakness years ago. This suggests insufficient security improvements have been made in the platform’s authentication mechanisms. Cybercriminals exploit session-hijacking vulnerabilities for various purposes. Stolen session data has been used to launch ransomware attacks, commit cryptocurrency theft, and conduct unauthorized financial transactions. The underground market for stolen session cookies remains active, with criminals regularly purchasing access credentials to compromise accounts at scale. For businesses running nopCommerce, a single compromised administrator session could grant attackers complete control over the ecommerce platform, enabling them to steal customer data, manipulate transactions, or deploy malware. The nopCommerce development team has released patches addressing this vulnerability. Users running version 4.70 or later excluding version 4.80.3 are protected. Those using version 4.80.3 or earlier must update immediately to version 4.90.3 or the latest available release. System administrators are urged to prioritize this update, as the vulnerability poses direct threats to customer data and financial assets. The update process should be completed as soon as possible to minimize exposure. This discovery highlights ongoing challenges in ecommerce platform security. The fact that a similar vulnerability existed in 2019 suggests that developers and businesses may not be adequately addressing session management best practices. Proper cookie invalidation upon logout is a fundamental security requirement that should be implemented across all authentication systems. Organizations using nopCommerce should conduct a security audit following the update to identify any suspicious account activities that may indicate prior exploitation. Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

The flaw allows attackers to hijack user accounts by exploiting captured session cookies, even after legitimate users have logged out.
Nathan Cole · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories