Falhas do tipo CWE-384

253 resultados

Fixação de Sessão

Fraqueza onde um atacante força a vítima a usar um identificador de sessão conhecido e controlado pelo atacante, em vez de receber um novo ID gerado pela aplicação. Após a vítima autenticar-se, o atacante reutiliza esse ID fixo para acessar a conta com os privilégios da vítima.

Exemplo

Um site envia um cookie de sessão (ex: SESSID=abc123) antes do login. O atacante convence a vítima a acessar um link contendo esse SESSID=abc123, depois que a vítima faz login, o atacante usa o mesmo cookie para acessar a conta autenticada da vítima.

Como mitigar

Gere sempre um novo ID de sessão após autenticação bem-sucedida, descartando qualquer ID anterior. Valide e resete a sessão no servidor a cada mudança de privilégio (login/logout). Use flags seguras no cookie: HttpOnly, Secure e SameSite.

CVE-2026-69214MEDIUMHttp4s: CookieJar middleware accepts arbitrary Set-Cookie domainEPSS 0.3%CVE-2025-37159MEDIUMAuthenticated Session Hijacking Allows Unauthorized Access in Network Switching SoftwareEPSS 0.3%CVE-2025-1412LOWSession Persistence After User-to-Bot ConversionEPSS 0.3%CVE-2026-92984HIGHHUBzero CMS through 2.2.32 Session Fixation via Query-String Session IdentifierEPSS 0.3%CVE-2024-48929MEDIUMUmbraco CMS Has Incomplete Server Termination During Explicit Sign-OutEPSS 0.3%CVE-2024-49344MEDIUMIBM OpenPages session fixationEPSS 0.3%CVE-2025-55266MEDIUMHCL Aftermarket DPC is affected by Session FixationEPSS 0.3%CVE-2024-28144MEDIUMBroken Access ControlEPSS 0.2%CVE-2024-42171MEDIUMHCL MyXalytics is affected by insufficient session expirationEPSS 0.2%CVE-2026-1758HIGHSession FixationEPSS 0.2%CVE-2026-31940HIGHSession Fixation in Chamilo LMSEPSS 0.2%CVE-2026-78428HIGHFlaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrentlyEPSS 0.2%CVE-2025-24503CRITICALA malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.EPSS 0.2%CVE-2026-11335MEDIUMtittuvarghese CollegeManagementSystem login-form.php session_start session fixiationEPSS 0.2%CVE-2026-86279MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiationEPSS 0.2%CVE-2026-86674MEDIUMningzichun Student Management System login.php session_start session fixiationEPSS 0.2%CVE-2025-65415MEDIUMdocuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.EPSS 0.2%CVE-2026-81181LOWSysReptor: Session Fixation in Password-Protected Shared NotesEPSS 0.2%CVE-2025-24502MEDIUMAn improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of anEPSS 0.2%CVE-2026-85238HIGHSession Fixation in MISP CustomAuth Authentication Allows Session HijackingEPSS 0.2%