VYPR

CWE-565

Reliance on Cookies without Validation and Integrity Checking

BaseIncomplete

Description

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (80)

page 3 of 4
  • CVE-2018-19224HigNov 12, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.

  • CVE-2016-15002HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack…

  • CVE-2026-75757HigAug 31, 2026
    risk 0.47cvss —epss 0.00

    Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state…

  • CVE-2023-32612HigJun 30, 2023
    risk 0.47cvss 7.2epss 0.01

    Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.

  • CVE-2022-28113HigApr 15, 2022
    risk 0.47cvss 7.2epss 0.04

    An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.

  • CVE-2021-41263HigNov 15, 2021
    risk 0.47cvss 8.3epss 0.01

    rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be…

  • CVE-2026-53871HigJun 17, 2026
    risk 0.46cvss 8.1epss 0.00

    Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass…

  • CVE-2024-28233HigMar 27, 2024
    risk 0.46cvss 8.1epss 0.00

    JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access…

  • CVE-2026-39963MedApr 15, 2026
    risk 0.45cvss 6.9epss 0.00

    Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as the domain parameter of setcookie(). An attacker who can influence the Host…

  • CVE-2022-29248HigMay 25, 2022
    risk 0.45cvss 8.0epss 0.01

    Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a…

  • CVE-2017-8034MedJul 17, 2017
    risk 0.43cvss 6.6epss 0.01

    The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA…

  • CVE-2025-48980MedOct 31, 2025
    risk 0.42cvss 6.5epss 0.00

    In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this…

  • CVE-2024-9820MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

  • CVE-2022-2615MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-26955MedDec 9, 2020
    risk 0.42cvss 6.5epss 0.01

    When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note:…

  • CVE-2021-36338MedJan 21, 2022
    risk 0.41cvss 6.3epss 0.00

    Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses…

  • CVE-2024-1551MedFeb 20, 2024
    risk 0.40cvss 6.1epss 0.01

    Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the…

  • CVE-2022-22785MedMay 18, 2022
    risk 0.39cvss 5.9epss 0.03

    The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies…

  • CVE-2026-69215MedSep 15, 2026
    risk 0.37cvss 6.8epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently…

  • CVE-2026-69214MedSep 15, 2026
    risk 0.37cvss 6.8epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejecting public suffixes. A malicious or…