github.com
https://github.com/intruderlabs/cvex/tree/main/Carestream/session-token-in-url CVE-2025-27955
MEDIUM
Record summary
CVE-2025-27955 has a selected CVSS score of 6.5 (medium).
Description
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2025 · Source: CVE List
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27955