Weaknesses of type CWE-384

253 results

Fixação de Sessão

É quando um atacante consegue forçar um usuário a usar um ID de sessão conhecido por ele, geralmente reutilizando a mesma sessão antes e depois do login. Depois que a vítima se autentica com aquele ID fixo, o atacante usa o mesmo ID para acessar a conta sem precisar da senha.

Example

Um site gera um cookie de sessão antes do login. O atacante envia um link com esse ID de sessão para a vítima (ex: www.site.com?jsessionid=ATACANTE123), a vítima clica e faz login normalmente, mas o atacante já tem acesso à mesma sessão autenticada porque o servidor nunca regenerou o ID após a autenticação.

How to mitigate

Regenere o ID de sessão imediatamente após um login bem-sucedido. Valide que o IP ou outros atributos da sessão não mudaram drasticamente entre requisições. Use flags Secure, HttpOnly e SameSite nos cookies de sessão para reduzir vetores de ataque.

CVE-2024-2260MEDIUMSession Fixation Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2022-33927MEDIUMDell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by takinEPSS 0.4%CVE-2020-1993LOWPAN-OS: GlobalProtect Portal PHP session fixation vulnerabilityEPSS 0.4%CVE-2023-3192MEDIUMSession Fixation in froxlor/froxlorEPSS 0.4%CVE-2024-11317CRITICALPHP Session FixationEPSS 0.4%CVE-2022-43529MEDIUMA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persistEPSS 0.4%CVE-2025-59841CRITICALFlagForgeCTF's Improper Session Handling Allows Access After LogoutEPSS 0.4%CVE-2025-45953CRITICALA vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change PassEPSS 0.4%CVE-2021-46279MEDIUMSession Fixation and Insufficient Session ExpirationEPSS 0.4%CVE-2024-56529HIGHMailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when EPSS 0.4%CVE-2025-42602HIGHImproper Authentication Vulnerability in Meon KYC solutionsEPSS 0.4%CVE-2025-28238CRITICALImproper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session EPSS 0.4%CVE-2026-75171CRITICALAn issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.EPSS 0.4%CVE-2024-24823MEDIUMgraylog2-server Session Fixation vulnerability through cookie injectionEPSS 0.4%CVE-2026-43827MEDIUMApache Shiro: Session fixation: new session is not created after login by defaultEPSS 0.4%CVE-2026-33757CRITICALOpenBao lacks user confirmation for OIDC direct callback modeEPSS 0.4%CVE-2025-4644MEDIUMUser Session Fixation after Account Removal in PayloadCMSEPSS 0.4%CVE-2026-86688HIGHSession id is not renewed on authentication in ash_authentication, allowing session fixationEPSS 0.4%CVE-2026-77614HIGHOpencast: Session fixation in login enables account takeover via crafted linkEPSS 0.4%CVE-2023-22479HIGHKubePi vulnerable to session fixation attack EPSS 0.4%