nopCommerce v4.10 and 4.80.3 is vulnerable to Insufficient Invalidation of Session Cookies. The application does not properly invalidate or expire authentication cookies after logout or session termination. An attacker who obtains a valid session cookie (e.g., via network interception, XSS, or system compromise) can continue to use the cookie to access privileged endpoints (such as /Admin) even after the legitimate user has logged out. This flaw enables session hijacking and privilege escalation, as the cookie remains valid beyond its intended lifecycle. POST /Admin HTTP/2 Host: Cookie: .Nop.Authentication=CfDJ8F***