Fallos del tipo CWE-384

253 resultados

Fixação de sessão

Ocorre quando a aplicação não regenera o ID da sessão após autenticação bem-sucedida, permitindo que um atacante force um usuário a usar um ID de sessão pré-conhecido. Depois que a vítima se autentica nessa sessão comprometida, o atacante consegue acessar a conta usando o ID que já controla.

Ejemplo

Um atacante envia ao usuário um link com um ID de sessão fixo (ex: PHPSESSID=abc123). A vítima clica, faz login normalmente, mas o servidor nunca muda o ID. Agora o atacante usa a mesma sessão para acessar a conta autenticada, roubando dados ou fazendo transações.

Cómo mitigar

Regenere o ID da sessão imediatamente após login bem-sucedido, descarte o ID antigo, e use um algoritmo criptograficamente forte para gerar novos IDs. Além disso, valide o IP/User-Agent da sessão e implemente timeout de inatividade.

CVE-2023-30307MEDIUMAn issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-REPSS 0.4%CVE-2018-0359A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could EPSS 0.4%CVE-2026-25101MEDIUMSession Fixation in BluditEPSS 0.4%CVE-2026-24352MEDIUMSession Fixation in PluXml CMSEPSS 0.4%CVE-2026-48545HIGHGradio < 6.15.0 Cookie Injection via Shared Proxy ClientEPSS 0.4%CVE-2024-22250HIGHSession Hijack Vulnerability in Deprecated EAP Browser PluginEPSS 0.3%CVE-2024-10318MEDIUMNGINX OpenID Connect VulnerabilityEPSS 0.3%CVE-2026-13707NONESession fixation attacks on improperly configured OAuth 1.0a toolsEPSS 0.3%CVE-2024-45368HIGHAutomationDirect DirectLogic H2-DM1E Session FixationEPSS 0.3%CVE-2024-42345MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly haEPSS 0.3%CVE-2024-42170MEDIUMHCL MyXalytics is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2026-81826CRITICALFlowintel Fails to Invalidate Active Sessions After Password ChangeEPSS 0.3%CVE-2026-2177MEDIUMSourceCodester Prison Management System Login session fixiationEPSS 0.3%CVE-2025-7014MEDIUMSession Hijacking in QRMenumPro's Menu PanelEPSS 0.3%CVE-2019-15612A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.EPSS 0.3%CVE-2026-40082MEDIUMCacti: Session Fixation via missing session_regenerate_id() after loginEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2025-53021MEDIUMA session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey paraEPSS 0.3%CVE-2025-46605MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixatiEPSS 0.3%CVE-2023-47798MEDIUMAccount lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsuEPSS 0.3%