VYPR

CWE-565

Reliance on Cookies without Validation and Integrity Checking

BaseIncomplete

Description

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (75)

page 1 of 4
  • CVE-2026-0257CriKEVMay 13, 2026
    risk 0.85cvss 9.1epss 0.94

    Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

  • CVE-2023-35885CriJun 20, 2023
    risk 0.70cvss 9.8epss 0.75

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

  • CVE-2008-5784CriDec 31, 2008
    risk 0.67cvss 9.8epss 0.07

    V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

  • CVE-2023-41084CriSep 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

  • CVE-2014-125112CriMar 26, 2026
    risk 0.64cvss 9.8epss 0.01

    Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of…

  • CVE-2022-50926CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.00

    WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without…

  • CVE-2025-65212CriJan 6, 2026
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file…

  • CVE-2025-2395CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.

  • CVE-2024-0947CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens. This issue…

  • CVE-2024-28288CriMar 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.

  • CVE-2023-3050CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2022-38297CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

  • CVE-2021-28171CriApr 6, 2021
    risk 0.64cvss 9.8epss 0.01

    The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.

  • CVE-2019-7266CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.05

    Linear eMerge 50P/5000P devices allow Authentication Bypass.

  • CVE-2018-20512CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.02

    EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

  • CVE-2018-5190CriApr 17, 2018
    risk 0.64cvss 9.8epss 0.01

    PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and pc_login_page.php.

  • CVE-2018-5455CriMar 5, 2018
    risk 0.64cvss 9.8epss 0.02

    A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack…

  • CVE-2017-7279CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.04

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

  • CVE-2023-32725CriDec 18, 2023
    risk 0.62cvss 9.6epss 0.01

    The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

  • CVE-2017-6896HigMar 14, 2017
    risk 0.60cvss 8.8epss 0.04

    Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.