Falhas do tipo CWE-384

253 resultados

Fixação de Sessão

Fraqueza onde um atacante força a vítima a usar um identificador de sessão conhecido e controlado pelo atacante, em vez de receber um novo ID gerado pela aplicação. Após a vítima autenticar-se, o atacante reutiliza esse ID fixo para acessar a conta com os privilégios da vítima.

Exemplo

Um site envia um cookie de sessão (ex: SESSID=abc123) antes do login. O atacante convence a vítima a acessar um link contendo esse SESSID=abc123, depois que a vítima faz login, o atacante usa o mesmo cookie para acessar a conta autenticada da vítima.

Como mitigar

Gere sempre um novo ID de sessão após autenticação bem-sucedida, descartando qualquer ID anterior. Valide e resete a sessão no servidor a cada mudança de privilégio (login/logout). Use flags seguras no cookie: HttpOnly, Secure e SameSite.

CVE-2023-4649MEDIUMSession Fixation in instantsoft/icms2EPSS 0.4%CVE-2024-2260MEDIUMSession Fixation Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2022-33927MEDIUMDell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by takinEPSS 0.4%CVE-2020-1993LOWPAN-OS: GlobalProtect Portal PHP session fixation vulnerabilityEPSS 0.4%CVE-2023-3192MEDIUMSession Fixation in froxlor/froxlorEPSS 0.4%CVE-2024-11317CRITICALPHP Session FixationEPSS 0.4%CVE-2022-43529MEDIUMA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persistEPSS 0.4%CVE-2025-59841CRITICALFlagForgeCTF's Improper Session Handling Allows Access After LogoutEPSS 0.4%CVE-2021-46279MEDIUMSession Fixation and Insufficient Session ExpirationEPSS 0.4%CVE-2025-45953CRITICALA vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change PassEPSS 0.4%CVE-2024-56529HIGHMailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when EPSS 0.4%CVE-2025-42602HIGHImproper Authentication Vulnerability in Meon KYC solutionsEPSS 0.4%CVE-2025-28238CRITICALImproper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session EPSS 0.4%CVE-2026-75171CRITICALAn issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.EPSS 0.4%CVE-2024-24823MEDIUMgraylog2-server Session Fixation vulnerability through cookie injectionEPSS 0.4%CVE-2026-43827MEDIUMApache Shiro: Session fixation: new session is not created after login by defaultEPSS 0.4%CVE-2026-33757CRITICALOpenBao lacks user confirmation for OIDC direct callback modeEPSS 0.4%CVE-2025-4644MEDIUMUser Session Fixation after Account Removal in PayloadCMSEPSS 0.4%CVE-2026-86688HIGHSession id is not renewed on authentication in ash_authentication, allowing session fixationEPSS 0.4%CVE-2026-77614HIGHOpencast: Session fixation in login enables account takeover via crafted linkEPSS 0.4%