VYPR

CWE-784

Reliance on Cookies without Validation and Integrity Checking in a Security Decision

VariantDraftLikelihood: High

Description

The product uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.

Attackers can easily modify cookies, within the browser or by implementing the client-side code outside of the browser. Attackers can bypass protection mechanisms such as authorization and authentication by modifying the cookie to contain an expected value.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (6)

  • CVE-2023-3050CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2026-60134HigJul 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

  • CVE-2026-45055HigMay 13, 2026
    risk 0.46cvss 8.1epss 0.00

    CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset…

  • CVE-2024-9820MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

  • CVE-2020-8184HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.03

    A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

  • CVE-2022-3083LowFeb 1, 2023
    risk 0.25cvss 3.9epss 0.00

    All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an…