CVE-2025-62781Medium· 5.0▾ SunlitPILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except for the currently active one. However, the current session’s token remains valid and is not refreshed. If an attacker has previously obtained this session token through another vulnerability, changing the password will not invalidate their access. As a result, the attacker can continue to act as the user even after the password has been changed. This vulnerability is fixed in 4.8.0.
pilos < 4.8.0Upgrade past the affected range:
pilos 4.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62523Medium· 6.3PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
CVE-2025-62524Medium· 5.3PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
CVE-2025-54547Medium· 5.3On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
CVE-2026-107275Medium· 6.8@fastify/jwt is a JSON Web Token plugin for the Fastify web framework
CVE-2025-61775NoneVickey is a Misskey-based microblogging platform
CVE-2024-8122Medium· 5.9The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA)