Fallos del tipo CWE-384

253 resultados

Fixação de sessão

Ocorre quando a aplicação não regenera o ID da sessão após autenticação bem-sucedida, permitindo que um atacante force um usuário a usar um ID de sessão pré-conhecido. Depois que a vítima se autentica nessa sessão comprometida, o atacante consegue acessar a conta usando o ID que já controla.

Ejemplo

Um atacante envia ao usuário um link com um ID de sessão fixo (ex: PHPSESSID=abc123). A vítima clica, faz login normalmente, mas o servidor nunca muda o ID. Agora o atacante usa a mesma sessão para acessar a conta autenticada, roubando dados ou fazendo transações.

Cómo mitigar

Regenere o ID da sessão imediatamente após login bem-sucedido, descarte o ID antigo, e use um algoritmo criptograficamente forte para gerar novos IDs. Além disso, valide o IP/User-Agent da sessão e implemente timeout de inatividade.

CVE-2025-1412LOWSession Persistence After User-to-Bot ConversionEPSS 0.3%CVE-2026-92984HIGHHUBzero CMS through 2.2.32 Session Fixation via Query-String Session IdentifierEPSS 0.3%CVE-2024-48929MEDIUMUmbraco CMS Has Incomplete Server Termination During Explicit Sign-OutEPSS 0.3%CVE-2024-49344MEDIUMIBM OpenPages session fixationEPSS 0.3%CVE-2025-55266MEDIUMHCL Aftermarket DPC is affected by Session FixationEPSS 0.3%CVE-2024-28144MEDIUMBroken Access ControlEPSS 0.2%CVE-2024-42171MEDIUMHCL MyXalytics is affected by insufficient session expirationEPSS 0.2%CVE-2026-1758HIGHSession FixationEPSS 0.2%CVE-2026-31940HIGHSession Fixation in Chamilo LMSEPSS 0.2%CVE-2026-78428HIGHFlaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrentlyEPSS 0.2%CVE-2025-24503CRITICALA malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.EPSS 0.2%CVE-2026-11335MEDIUMtittuvarghese CollegeManagementSystem login-form.php session_start session fixiationEPSS 0.2%CVE-2026-86279MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiationEPSS 0.2%CVE-2026-86674MEDIUMningzichun Student Management System login.php session_start session fixiationEPSS 0.2%CVE-2025-65415MEDIUMdocuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.EPSS 0.2%CVE-2026-81181LOWSysReptor: Session Fixation in Password-Protected Shared NotesEPSS 0.2%CVE-2025-24502MEDIUMAn improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of anEPSS 0.2%CVE-2026-85238HIGHSession Fixation in MISP CustomAuth Authentication Allows Session HijackingEPSS 0.2%CVE-2025-65681LOWAn issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to seEPSS 0.2%CVE-2026-41839MEDIUMSpring Framework Escalation via Session Fixation in WebFluxEPSS 0.2%