High severity8.8NVD Advisory· Published May 3, 2022· Updated Jun 17, 2026
CVE-2022-23063
CVE-2022-23063
Description
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:shopizer:shopizer:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:shopizer:shopizer:*:*:*:*:*:*:*:*range: >=2.3.0,<=3.0.1
- (no CPE)range: 2.3.0 - 3.0.1
- (no CPE)range: 2.3.0
Patches
Vulnerability mechanics
References
2- github.com/shopizer-ecommerce/shopizer/blob/3.0.1/sm-shop/src/main/java/com/salesmanager/shop/store/api/v1/customer/AuthenticateCustomerApi.javanvdExploitThird Party Advisory
- www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23063nvdThird Party Advisory
News mentions
0No linked articles in our index yet.