CWE-565

Reliance on Cookies without Validation and Integrity Checking

Parent: CWE-642 - External Control of Critical State Data

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

74 vulnerabilities with CWE-565
CVE-2023-45128 CRITICAL
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper CSRF Token Validation
CVSS 10.0
CVE-2023-41084 CRITICAL
Web App <version> - Info Disclosure
CVSS 10.0
CVE-2023-3747 MEDIUM
Cloudflare WARP - Client-Side Enforcement Bypass via Local Date Manipulation
CVSS 5.5
CVE-2023-32612 HIGH
WL-WN531AX2 <2023526 - Command Injection
CVSS 7.2
CVE-2023-35885 CRITICAL
CloudPanel 2.0.0-2.3.0 - Unauthenticated Remote Code Execution via File Manager Cookie
CVSS 9.8
CVE-2023-3050 CRITICAL
TMT Lockcell Firmware < 15.0 - Authentication Bypass via Unvalidated Cookie
CVSS 9.8
CVE-2022-50926 CRITICAL
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
CVSS 9.8
CVE-2022-3083 LOW
Landis+Gyr E850 (ZMQ200) - Info Disclosure
CVSS 3.9
CVE-2022-38297 CRITICAL
UCMS v1.6.0 - Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2022-36032 MEDIUM
ReactPHP HTTP 0.7.0-1.7.0 - Cookie Prefix Spoofing via URL Decoding
CVSS 5.3
CVE-2022-2615 MEDIUM
Google Chrome <104.0.5112.79 - CSRF
CVSS 6.5
CVE-2022-35284 HIGH
IBM Security Verify Information Queue 10.0.2 - Info Disclosure
CVSS 7.5
CVE-2022-30620 HIGH
Cellinx Camera - Privilege Escalation
CVSS 8.2
CVE-2022-29248 HIGH
Guzzle < 6.5.6 - Cookie Domain Validation Bypass
CVSS 8.0
CVE-2022-22785 MEDIUM
Zoom Meetings < 5.10.0 - Session Cookie Spoofing via Improper Domain Validation
CVSS 5.9
CVE-2022-28113 HIGH
FANTEC GmbH MWiD25-DS Firmware <2.000.030 - RCE
CVSS 7.2
CVE-2022-1148 MEDIUM
GitLab CE/EE <14.7.7-14.9.2 - Info Disclosure
CVSS 5.3
CVE-2021-47706 HIGH
COMMAX Biometric Access Control System 1.0.0 - Auth Bypass
CVE-2021-20450 MEDIUM
IBM Cognos Controller <11.0.0 - Open Redirect
CVSS 4.3
CVE-2021-36338 MEDIUM
Unisphere for PowerMax <9.2.2.2 - Privilege Escalation
CVSS 6.3
CVE-2021-41819 HIGH
Ruby CGI < 2.6.8 and CGI Gem < 0.3.1 - Cookie Security Prefix Bypass
CVSS 7.5
CVE-2021-41263 HIGH
rails_multisite <4 - Info Disclosure
CVSS 8.3
CVE-2021-3818 MEDIUM
Grav < 1.7.22 - Reliance on Cookies without Validation and Integrity Checking
CVSS 5.3
CVE-2021-33842 HIGH
Circutor SGE-PLC1000 <0.9.2b - Auth Bypass
CVSS 8.8
CVE-2021-29624 MEDIUM
fastify-csrf < 3.1.0 - Cross-Site Request Forgery Protection Bypass via Subdomain Cookie Handling
CVSS 6.5
Details
Vulnerabilities 74