VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 3 of 22
  • CVE-2017-15304CriOct 15, 2017
    risk 0.64cvss 9.8epss 0.01

    /bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin password change.

  • CVE-2016-10405CriSep 7, 2017
    risk 0.64cvss 9.8epss 0.02

    Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.

  • CVE-2015-1820CriAug 9, 2017
    risk 0.64cvss 9.8epss 0.04

    REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

  • CVE-2015-1174CriAug 2, 2017
    risk 0.64cvss 9.8epss 0.03

    Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.

  • CVE-2016-9125CriMar 28, 2017
    risk 0.64cvss 9.8epss 0.03

    Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for…

  • CVE-2019-7747CriFeb 11, 2019
    risk 0.63cvss 9.6epss 0.01

    DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.

  • CVE-2019-10008HigApr 24, 2019
    risk 0.62cvss 8.8epss 0.19

    Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect…

  • CVE-2025-24503CriJan 30, 2025
    risk 0.60cvss epss 0.00

    A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

  • CVE-2026-40010CriMay 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended…

  • CVE-2025-69602CriJan 28, 2026
    risk 0.59cvss 9.1epss 0.00

    A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing…

  • CVE-2025-45953CriApr 28, 2025
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

  • CVE-2025-27661CriMar 5, 2025
    risk 0.59cvss 9.1epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.

  • CVE-2023-52268CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.01

    The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.

  • CVE-2024-23590CriNov 4, 2024
    risk 0.59cvss 9.1epss 0.01

    Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.

  • CVE-2021-42761CriFeb 16, 2023
    risk 0.59cvss 9.0epss 0.01

    A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to…

  • CVE-2022-36437CriDec 29, 2022
    risk 0.59cvss 9.1epss 0.01

    The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and…

  • CVE-2020-12258CriMay 18, 2020
    risk 0.59cvss 9.1epss 0.02

    rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.

  • CVE-2020-9370CriMar 5, 2020
    risk 0.59cvss 9.1epss 0.01

    HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.

  • CVE-2020-8990CriFeb 20, 2020
    risk 0.59cvss 9.1epss 0.01

    Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.

  • CVE-2024-38513CriJul 1, 2024
    risk 0.58cvss 10.0epss 0.01

    Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a…