CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

392 vulnerabilities with CWE-384
CVE-2022-34536 HIGH
Digital Watchdog DW MEGApix IP Cameras - Session Hijacking via Crafted Session Token
CVSS 7.5
CVE-2022-22681 HIGH
Synology Photo Station <6.8.16-3506 - Auth Bypass
CVSS 8.1
CVE-2022-25896 MEDIUM
passport <0.6.0 - Info Disclosure
CVSS 4.8
CVE-2022-24444 MEDIUM
Silverstripe framework <4.10 - Info Disclosure
CVSS 6.5
CVE-2022-27305 HIGH
Gibbon v23 - Info Disclosure
CVSS 8.8
CVE-2022-1849 MEDIUM
filegator/filegator <7.8.0 - Info Disclosure
CVSS 5.4
CVE-2022-26591 HIGH
MWiD25-DS Firmware <2.000.030 - Info Disclosure
CVSS 7.5
CVE-2022-24781 HIGH
Geon <1.1.0 - Info Disclosure
CVSS 7.1
CVE-2022-24745 MEDIUM
Shopware - Info Disclosure
CVSS 4.8
CVE-2022-22551 HIGH
DELL EMC AppSync <4.3 - Info Disclosure
CVSS 8.3
CVE-2021-3740 MEDIUM
chatwoot <2.4.0 - Session Fixation
CVSS 6.8
CVE-2021-36394 CRITICAL
Moodle - RCE
CVSS 9.8
CVE-2021-42761 CRITICAL
FortiWeb <6.4 - Session Fixation
CVSS 9.0
CVE-2021-29368 HIGH
CuppaCMS - Session Fixation
CVSS 8.8
CVE-2021-46279 MEDIUM
Lanner Inc IAC-AST2500A <1.10.0 - Session Fixation
CVSS 5.8
CVE-2021-38869 CRITICAL
IBM QRadar SIEM <7.5 - Info Disclosure
CVSS 9.8
CVE-2021-39066 HIGH
IBM Financial Transaction Manager 3.2.4 - Info Disclosure
CVSS 8.8
CVE-2021-20151 CRITICAL
Trendnet AC2600 TEW-827DRU <2.08B01 - Session Hijacking
CVSS 10.0
CVE-2021-31745 HIGH
Pluck-CMS Pluck <4.7.15 - Session Fixation
CVSS 7.5
CVE-2021-41246 MEDIUM
Express OpenID Connect <2.5.1 - Session Fixation
CVSS 4.6
CVE-2021-41268 MEDIUM
Symfony/SecurityBundle <5.3.12 - Info Disclosure
CVSS 6.5
CVE-2021-42073 HIGH
Barrier <2.4.0 - Info Disclosure
CVSS 8.2
CVE-2021-41553 CRITICAL
ARCHIBUS Web Central 21.3.3.815 - Info Disclosure
CVSS 9.8
CVE-2021-35948 MEDIUM
ownCloud Server <10.8.0 - Auth Bypass
CVSS 5.4
CVE-2021-22237 MEDIUM
GitLab <13.12.9, <14.0.7, <14.1.2 - Info Disclosure
CVSS 6.6
Details
Vulnerabilities 392