CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

404 vulnerabilities with CWE-384
CVE-2022-40226 HIGH
SICAM P850 <V3.10 - Info Disclosure
CVSS 7.5
CVE-2022-34334 MEDIUM
IBM Sterling Partner Engagement Manager 2.0 - Privilege Escalation
CVSS 6.5
CVE-2022-40630 MEDIUM
Tacitine Firewall <22.20.1 - Session Fixation
CVSS 6.5
CVE-2022-3269 CRITICAL
ikus060/rdiffweb <2.4.7 - Info Disclosure
CVSS 9.8
CVE-2022-38369 HIGH
Apache IoTDB 0.13.0 - Session Fixation
CVSS 8.8
CVE-2022-38054 CRITICAL
Apache Airflow <2.3.3 - Info Disclosure
CVSS 9.8
CVE-2022-31798 MEDIUM
Nortek Linear eMerge E3-Series < 0.32-07p - Cross-Site Scripting and Session Fixation via CardFormatNo Parameter
CVSS 6.1
CVE-2022-2997 HIGH
GitHub snipe/snipe-it <6.0.10 - Info Disclosure
CVSS 8.0
CVE-2022-30605 HIGH
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Session Fixation via Crafted HTTP Request
CVSS 8.8
CVE-2022-2820 HIGH
GitHub repository namelessmc/nameless <v2.0.2 - Info Disclosure
CVSS 7.0
CVE-2022-33927 MEDIUM
Dell Wyse Management Suite <3.6.1 - Session Fixation
CVSS 5.4
CVE-2022-34536 HIGH
Digital Watchdog DW MEGApix IP Cameras - Session Hijacking via Crafted Session Token
CVSS 7.5
CVE-2022-22681 HIGH
Synology Photo Station <6.8.16-3506 - Auth Bypass
CVSS 8.1
CVE-2022-25896 MEDIUM
passport < 0.6.0 - Session Fixation via Session Regeneration
CVSS 4.8
CVE-2022-24444 MEDIUM
Silverstripe framework <4.10 - Info Disclosure
CVSS 6.5
CVE-2022-27305 HIGH
Gibbon < 23.0.02 - Session Fixation
CVSS 8.8
CVE-2022-1849 MEDIUM
filegator/filegator <7.8.0 - Info Disclosure
CVSS 5.4
CVE-2022-26591 HIGH
MWiD25-DS Firmware <2.000.030 - Info Disclosure
CVSS 7.5
CVE-2022-24781 HIGH
Geon - Session Fixation via UUID Spoofing
CVSS 7.1
CVE-2022-24745 MEDIUM
Shopware < 6.4.8.2 - Session Fixation via HTTP Cache
CVSS 4.8
CVE-2022-22551 HIGH
DELL EMC AppSync <4.3 - Info Disclosure
CVSS 8.3
CVE-2021-3740 MEDIUM
chatwoot < 2.4.0 - Session Fixation via Password Change
CVSS 6.8
CVE-2021-36394 CRITICAL
Moodle - Remote Code Execution in Shibboleth Authentication Plugin
CVSS 9.8
CVE-2021-42761 CRITICAL
FortiWeb 5.9.0-5.9.1, 6.0.0-6.0.7, 6.1.0-6.1.2, 6.2.0-6.2.6, 6.3.0-6.3.16, 6.4 - Unauthenticated Session Fixation
CVSS 9.0
CVE-2021-29368 HIGH
CuppaCMS < 2019-11-12 - Session Fixation
CVSS 8.8
Details
Vulnerabilities 404