VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 1 of 22
  • CVE-2017-12965CriAug 23, 2017
    risk 0.68cvss 9.8epss 0.16

    Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

  • CVE-2019-18418CriOct 24, 2019
    risk 0.67cvss 9.8epss 0.04

    clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

  • CVE-2018-11714CriJun 4, 2018
    risk 0.67cvss 9.8epss 0.35

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

  • CVE-2015-4594CriJan 10, 2017
    risk 0.67cvss 9.8epss 0.06

    eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

  • CVE-2018-18925CriNov 4, 2018
    risk 0.66cvss 9.8epss 0.31

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.

  • CVE-2025-63224CriNov 19, 2025
    risk 0.65cvss 10.0epss 0.01

    The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same…

  • CVE-2025-63216CriNov 18, 2025
    risk 0.65cvss 10.0epss 0.01

    The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same…

  • CVE-2025-52689CriJul 16, 2025
    risk 0.65cvss 9.8epss 0.12

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.

  • CVE-2024-11317CriDec 5, 2024
    risk 0.65cvss 10.0epss 0.00

    Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2021-20151CriDec 30, 2021
    risk 0.65cvss 10.0epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a…

  • CVE-2025-67446CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication…

  • CVE-2026-24352CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.00

    PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was…

  • CVE-2026-23796CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was…

  • CVE-2025-53826CriJul 15, 2025
    risk 0.64cvss 9.8epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs…

  • CVE-2025-45949CriApr 28, 2025
    risk 0.64cvss 9.8epss 0.01

    A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable…

  • CVE-2025-28242CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.02

    Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

  • CVE-2025-28238CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.

  • CVE-2022-40916CriFeb 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

  • CVE-2024-57052CriJan 27, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.

  • CVE-2024-13279CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.