CVE Explorer
CVE-2025-62781
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except for the currently active one. However, the current session’s token remains valid and is not refreshed. If an attacker has previously obtained this session token through another vulnerability, changing the password will not invalidate their access. As a result, th
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"PILOS","vendor":"THM-Health","versions":[{"status":"affected","version":"< 4.8.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:862f896bfb37d82bb11dfe55267b39e3c62e0cef5798fd861a8f97fda6a07111 · sha256:b77cd7151869987d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:862f896bfb37d82bb11dfe55267b39e3c62e0cef5798fd861a8f97fda6a07111 · sha256:b77cd7151869987d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-613","description":"CWE-613: Insufficient Session Expiration","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:862f896bfb37d82bb11dfe55267b39e3c62e0cef5798fd861a8f97fda6a07111 · sha256:b77cd7151869987d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/THM-Health/PILOS/security/advisories/GHSA-m8w5-8w3h-72wm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/THM-Health/PILOS/security/advisories/GHSA-m8w5-8w3h-72wm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:862f896bfb37d82bb11dfe55267b39e3c62e0cef5798fd861a8f97fda6a07111 · sha256:b77cd7151869987d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.