CWE-384
Session Fixation
Description
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61
CVEs mapped to this weakness (435)
page 3 of 22| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-15304 | Cri | 0.64 | 9.8 | 0.01 | Oct 15, 2017 | /bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin password change. | ||
| CVE-2016-10405 | Cri | 0.64 | 9.8 | 0.02 | Sep 7, 2017 | Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors. | ||
| CVE-2015-1820 | Cri | 0.64 | 9.8 | 0.04 | Aug 9, 2017 | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. | ||
| CVE-2015-1174 | Cri | 0.64 | 9.8 | 0.03 | Aug 2, 2017 | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id. | ||
| CVE-2016-9125 | Cri | 0.64 | 9.8 | 0.03 | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for… | ||
| CVE-2019-7747 | Cri | 0.63 | 9.6 | 0.01 | Feb 11, 2019 | DbNinja 3.2.7 allows session fixation via the data.php sessid parameter. | ||
| CVE-2019-10008 | Hig | 0.62 | 8.8 | 0.19 | Apr 24, 2019 | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect… | ||
| CVE-2025-24503 | Cri | 0.60 | — | 0.00 | Jan 30, 2025 | A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. | ||
| CVE-2026-40010 | Cri | 0.59 | 9.1 | 0.00 | May 6, 2026 | Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended… | ||
| CVE-2025-69602 | Cri | 0.59 | 9.1 | 0.00 | Jan 28, 2026 | A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing… | ||
| CVE-2025-45953 | Cri | 0.59 | 9.1 | 0.00 | Apr 28, 2025 | A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely | ||
| CVE-2025-27661 | Cri | 0.59 | 9.1 | 0.01 | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004. | ||
| CVE-2023-52268 | Cri | 0.59 | 9.1 | 0.01 | Nov 12, 2024 | The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub. | ||
| CVE-2024-23590 | Cri | 0.59 | 9.1 | 0.01 | Nov 4, 2024 | Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue. | ||
| CVE-2021-42761 | Cri | 0.59 | 9.0 | 0.01 | Feb 16, 2023 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to… | ||
| CVE-2022-36437 | Cri | 0.59 | 9.1 | 0.01 | Dec 29, 2022 | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and… | ||
| CVE-2020-12258 | Cri | 0.59 | 9.1 | 0.02 | May 18, 2020 | rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259. | ||
| CVE-2020-9370 | Cri | 0.59 | 9.1 | 0.01 | Mar 5, 2020 | HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. | ||
| CVE-2020-8990 | Cri | 0.59 | 9.1 | 0.01 | Feb 20, 2020 | Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation. | ||
| CVE-2024-38513 | Cri | 0.58 | 10.0 | 0.01 | Jul 1, 2024 | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a… |
- risk 0.64cvss 9.8epss 0.01
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin password change.
- risk 0.64cvss 9.8epss 0.02
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
- risk 0.64cvss 9.8epss 0.04
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
- risk 0.64cvss 9.8epss 0.03
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
- risk 0.64cvss 9.8epss 0.03
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for…
- risk 0.63cvss 9.6epss 0.01
DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
- risk 0.62cvss 8.8epss 0.19
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect…
- risk 0.60cvss —epss 0.00
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
- risk 0.59cvss 9.1epss 0.00
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended…
- risk 0.59cvss 9.1epss 0.00
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing…
- risk 0.59cvss 9.1epss 0.00
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely
- risk 0.59cvss 9.1epss 0.01
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.
- risk 0.59cvss 9.1epss 0.01
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.
- risk 0.59cvss 9.1epss 0.01
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
- risk 0.59cvss 9.0epss 0.01
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to…
- risk 0.59cvss 9.1epss 0.01
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and…
- risk 0.59cvss 9.1epss 0.02
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.
- risk 0.59cvss 9.1epss 0.01
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
- risk 0.59cvss 9.1epss 0.01
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
- risk 0.58cvss 10.0epss 0.01
Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a…