CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

392 vulnerabilities with CWE-384
CVE-2024-48929 MEDIUM
Umbraco <13.5.2-10.8.7 - Info Disclosure
CVSS 4.2
CVE-2024-10158 MEDIUM
PHPGurukul Boat Booking System 1.0 - Session Fixation
CVSS 4.3
CVE-2024-8643 CRITICAL
Oceanic Software ValeApp <2.0.0 - Session Fixation
CVSS 9.8
CVE-2024-45368 HIGH
H2-DM1E PLC - Auth Bypass
CVSS 8.8
CVE-2024-42345 MEDIUM
SINEMA Remote Connect Server <V3.2 SP2 - Auth Bypass
CVSS 4.3
CVE-2024-7341 HIGH
Keycloak - Session Fixation
CVSS 7.1
CVE-2024-37829 HIGH
Outline <= 0.76.1 - SSRF
CVSS 8.8
CVE-2024-38513 CRITICAL
Fiber <2.52.5 - Session Fixation
CVSS 10.0
CVE-2024-24552 HIGH
Bludit - Auth Bypass
CVSS 8.8
CVE-2024-25977 HIGH
Application - Auth Bypass
CVSS 7.3
CVE-2024-23193 MEDIUM
Open-xchange OX App Suite < 8.22 - Information Disclosure
CVSS 5.3
CVE-2024-2260 MEDIUM
ZenML < - Session Fixation
CVSS 4.2
CVE-2024-0157 MEDIUM
Dell Storage Resource Manager <4.9.0.0 - Privilege Escalation
CVSS 5.9
CVE-2024-30262 MEDIUM
Contao <4.13.40 - Info Disclosure
CVSS 5.9
CVE-2024-31221 MEDIUM
Sunshine <0.23.0 - Info Disclosure
CVSS 5.9
CVE-2024-2639 MEDIUM
Bdtask Wholesale Inventory Management System <20240311 - Session Fi...
CVSS 4.3
CVE-2024-28197 HIGH
Zitadel < 2.44.3 - XSS
CVSS 7.5
CVE-2024-22250 HIGH
VMware Enhanced Authentication Plug-in - Session Hijack
CVSS 7.8
CVE-2024-22318 MEDIUM
IBM i Access Client Solutions <1.1.2-1.1.4, <1.1.4.3-1.1.9.4 - Info...
CVSS 5.1
CVE-2024-24823 MEDIUM
Graylog <5.1.11-5.2.4 - Privilege Escalation
CVSS 5.7
CVE-2024-23679 CRITICAL
Enonic XP <7.7.4 - Info Disclosure
CVSS 9.8
CVE-2024-0351 LOW
SourceCodester Engineers Online Portal 1.0 - Info Disclosure
CVSS 3.1
CVE-2023-53776 HIGH
Screen SFT DAB 1.9.3 - Auth Bypass
CVSS 8.8
CVE-2023-53775 MEDIUM
Screen SFT DAB 1.9.3 - Auth Bypass
CVSS 6.5
CVE-2023-53741 HIGH
Screen SFT DAB 1.9.3 - Auth Bypass
CVSS 8.1
Details
Vulnerabilities 392