CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

404 vulnerabilities with CWE-384
CVE-2024-31221 MEDIUM
lizardbyte/sunshine 0.10.0-0.22.9 - Session Fixation via Device Unpairing Bypass
CVSS 5.9
CVE-2024-2639 MEDIUM
Bdtask Wholesale Inventory Management System <20240311 - Session Fi...
CVSS 4.3
CVE-2024-28197 HIGH
Zitadel < 2.44.3 - Session Hijacking via Subdomain Cookie Access
CVSS 7.5
CVE-2024-22250 HIGH
VMware Enhanced Authentication Plug-in - Session Hijack
CVSS 7.8
CVE-2024-22318 MEDIUM
IBM i Access Client Solutions <1.1.2-1.1.4, <1.1.4.3-1.1.9.4 - Info...
CVSS 5.1
CVE-2024-24823 MEDIUM
Graylog <5.1.11-5.2.4 - Privilege Escalation
CVSS 5.7
CVE-2024-23679 CRITICAL
Enonic XP < 7.7.4 - Unauthenticated Session Fixation
CVSS 9.8
CVE-2024-0351 LOW
SourceCodester Engineers Online Portal 1.0 - Info Disclosure
CVSS 3.1
CVE-2023-53776 HIGH
Screen SFT DAB 1.9.3 - Authentication Bypass via Session Fixation
CVSS 8.8
CVE-2023-53775 MEDIUM
Screen SFT DAB 1.9.3 - Unauthenticated Authentication Bypass via Session Fixation
CVSS 6.5
CVE-2023-53741 HIGH
Screen SFT DAB Series - Compact Radio DAB Transmitter 1.9.3 - Authentication Bypass via IP Session Reuse
CVSS 8.1
CVE-2023-52268 CRITICAL
FreeScout End-User Portal <1.0.65 - Auth Bypass
CVSS 9.1
CVE-2023-50176 HIGH
Fortinet FortiOS <7.4.3, <7.2.7, <7.0.13 - RCE
CVSS 7.5
CVE-2023-38018 MEDIUM
IBM Aspera Shares 1.10.0 PL2 - Privilege Escalation
CVSS 6.3
CVE-2023-30307 MEDIUM
TP-LINK TL-R473GP-AC, XDR6020, TL-R479GP-AC, TL-R4239G, TL-WAR1200L, TL-R476G - TCP Session Hijacking
CVSS 5.3
CVE-2023-38002 MEDIUM
IBM Storage Scale <5.1.9.2 - Privilege Escalation
CVSS 5.0
CVE-2023-50270 MEDIUM
Apache DolphinScheduler 1.3.8-3.2.0 - Insufficient Session Expiration
CVSS 6.5
CVE-2023-45718 LOW
HCL Sametime 11.5-12.0.1 - Insufficient Session Expiration in Web Client
CVSS 3.9
CVE-2023-47798 MEDIUM
Liferay Portal/DXP <7.3.0 - Privilege Escalation
CVSS 5.4
CVE-2023-50941 MEDIUM
IBM PowerSC <2.2 - Privilege Escalation
CVSS 6.3
CVE-2023-52353 HIGH
Mbed TLS < 3.5.2 - Session Fixation via TLS Version Mishandling
CVSS 7.5
CVE-2023-50920 MEDIUM
GL.iNet <4.5.0 - Privilege Escalation
CVSS 5.5
CVE-2023-6913 HIGH
Imou Life 6.7.0 - Session Hijacking via QR Code WebView Handling
CVSS 8.1
CVE-2023-49804 MEDIUM
Uptime Kuma <1.23.9 - Info Disclosure
CVSS 6.7
CVE-2023-48929 CRITICAL
Franklin Fueling Systems SSA <1.6.24.492 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 404