VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (453)

page 12 of 23
  • CVE-2026-43827MedMay 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions,…

  • CVE-2026-31940HigApr 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in…

  • CVE-2026-24894HigFeb 12, 2026
    risk 0.42cvss 7.5epss 0.00

    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the…

  • CVE-2023-53775MedDec 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify…

  • CVE-2024-42171MedJan 11, 2025
    risk 0.42cvss 6.4epss 0.00

    HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

  • CVE-2023-6787MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the…

  • CVE-2024-28197HigMar 11, 2024
    risk 0.42cvss 7.5epss 0.00

    Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take…

  • CVE-2023-3711MedSep 12, 2023
    risk 0.42cvss 6.4epss 0.01

    Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective…

  • CVE-2023-22479HigJan 10, 2023
    risk 0.42cvss 7.5epss 0.00

    KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4.

  • CVE-2022-44788MedNov 21, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.

  • CVE-2022-34334MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.

  • CVE-2022-40630MedSep 23, 2022
    risk 0.42cvss 6.5epss 0.01

    This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker…

  • CVE-2022-24444MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

  • CVE-2020-25152MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.

  • CVE-2021-21671HigJun 30, 2021
    risk 0.42cvss 7.5epss 0.02

    Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

  • CVE-2021-32676MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk…

  • CVE-2020-15018MedJun 24, 2020
    risk 0.42cvss 6.5epss 0.01

    playSMS through 1.4.3 is vulnerable to session fixation.

  • CVE-2020-12467MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.

  • CVE-2020-5290MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by, for example, exploiting a stored XSS payload in a CTF…

  • CVE-2019-8116HigNov 5, 2019
    risk 0.42cvss 7.5epss 0.02

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.