Weaknesses of type CWE-384

253 results

Fixação de Sessão

É quando um atacante consegue forçar um usuário a usar um ID de sessão conhecido por ele, geralmente reutilizando a mesma sessão antes e depois do login. Depois que a vítima se autentica com aquele ID fixo, o atacante usa o mesmo ID para acessar a conta sem precisar da senha.

Example

Um site gera um cookie de sessão antes do login. O atacante envia um link com esse ID de sessão para a vítima (ex: www.site.com?jsessionid=ATACANTE123), a vítima clica e faz login normalmente, mas o atacante já tem acesso à mesma sessão autenticada porque o servidor nunca regenerou o ID após a autenticação.

How to mitigate

Regenere o ID de sessão imediatamente após um login bem-sucedido. Valide que o IP ou outros atributos da sessão não mudaram drasticamente entre requisições. Use flags Secure, HttpOnly e SameSite nos cookies de sessão para reduzir vetores de ataque.

CVE-2023-30307MEDIUMAn issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-REPSS 0.4%CVE-2018-0359A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could EPSS 0.4%CVE-2026-25101MEDIUMSession Fixation in BluditEPSS 0.4%CVE-2026-24352MEDIUMSession Fixation in PluXml CMSEPSS 0.4%CVE-2026-48545HIGHGradio < 6.15.0 Cookie Injection via Shared Proxy ClientEPSS 0.4%CVE-2024-22250HIGHSession Hijack Vulnerability in Deprecated EAP Browser PluginEPSS 0.3%CVE-2024-10318MEDIUMNGINX OpenID Connect VulnerabilityEPSS 0.3%CVE-2026-13707NONESession fixation attacks on improperly configured OAuth 1.0a toolsEPSS 0.3%CVE-2024-45368HIGHAutomationDirect DirectLogic H2-DM1E Session FixationEPSS 0.3%CVE-2024-42345MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly haEPSS 0.3%CVE-2024-42170MEDIUMHCL MyXalytics is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2026-81826CRITICALFlowintel Fails to Invalidate Active Sessions After Password ChangeEPSS 0.3%CVE-2026-2177MEDIUMSourceCodester Prison Management System Login session fixiationEPSS 0.3%CVE-2025-7014MEDIUMSession Hijacking in QRMenumPro's Menu PanelEPSS 0.3%CVE-2019-15612A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.EPSS 0.3%CVE-2026-40082MEDIUMCacti: Session Fixation via missing session_regenerate_id() after loginEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2025-53021MEDIUMA session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey paraEPSS 0.3%CVE-2025-46605MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixatiEPSS 0.3%CVE-2023-47798MEDIUMAccount lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsuEPSS 0.3%