Falhas do tipo CWE-384

253 resultados

Fixação de Sessão

Fraqueza onde um atacante força a vítima a usar um identificador de sessão conhecido e controlado pelo atacante, em vez de receber um novo ID gerado pela aplicação. Após a vítima autenticar-se, o atacante reutiliza esse ID fixo para acessar a conta com os privilégios da vítima.

Exemplo

Um site envia um cookie de sessão (ex: SESSID=abc123) antes do login. O atacante convence a vítima a acessar um link contendo esse SESSID=abc123, depois que a vítima faz login, o atacante usa o mesmo cookie para acessar a conta autenticada da vítima.

Como mitigar

Gere sempre um novo ID de sessão após autenticação bem-sucedida, descartando qualquer ID anterior. Valide e resete a sessão no servidor a cada mudança de privilégio (login/logout). Use flags seguras no cookie: HttpOnly, Secure e SameSite.

CVE-2020-36913HIGHAll-Dynamics Software enlogic:show 2.0.2 Session Fixation Authentication BypassEPSS 0.4%CVE-2023-26260MEDIUMOXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacEPSS 0.4%CVE-2023-30307MEDIUMAn issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-REPSS 0.4%CVE-2026-25101MEDIUMSession Fixation in BluditEPSS 0.4%CVE-2018-0359A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could EPSS 0.4%CVE-2026-24352MEDIUMSession Fixation in PluXml CMSEPSS 0.4%CVE-2026-48545HIGHGradio < 6.15.0 Cookie Injection via Shared Proxy ClientEPSS 0.4%CVE-2024-10318MEDIUMNGINX OpenID Connect VulnerabilityEPSS 0.3%CVE-2024-22250HIGHSession Hijack Vulnerability in Deprecated EAP Browser PluginEPSS 0.3%CVE-2026-13707NONESession fixation attacks on improperly configured OAuth 1.0a toolsEPSS 0.3%CVE-2024-45368HIGHAutomationDirect DirectLogic H2-DM1E Session FixationEPSS 0.3%CVE-2024-42345MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly haEPSS 0.3%CVE-2024-42170MEDIUMHCL MyXalytics is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2026-81826CRITICALFlowintel Fails to Invalidate Active Sessions After Password ChangeEPSS 0.3%CVE-2026-2177MEDIUMSourceCodester Prison Management System Login session fixiationEPSS 0.3%CVE-2025-7014MEDIUMSession Hijacking in QRMenumPro's Menu PanelEPSS 0.3%CVE-2026-40082MEDIUMCacti: Session Fixation via missing session_regenerate_id() after loginEPSS 0.3%CVE-2019-15612A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.EPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2025-53021MEDIUMA session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey paraEPSS 0.3%