CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Feb 8, 2024 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote...Show more |
Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, even if for different u...Show more |
IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.
|
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum. |
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes. |
1Gl Inet 12Gl A1300 Firmware Gl Ar300m FirmwareGl Ar750 Firmware+9 moreJun 17, 2026 Jan 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authenticatio...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Jan 9, 2024 N/A· v4 3.5 LOW· v3 2.6 LOW· v2 A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. It is possible to initiate the attack rem...Show more |
A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0. This vulnerability could allow an attacker to hijack user accounts due to the QR code functionality not properly f...Show more |
2Dockge.kuma Uptime.kuma2Dockge Uptime KumaJun 17, 2026 Dec 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behav...Show more |
1Franklin Electric 1System Sentinel Anyware Jun 17, 2026 Dec 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensi...Show more |
Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Blue...Show more |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate t...Show more |
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
|
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareJun 17, 2026 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.
|
1Southrivertech 2Titan Mft Server Titan Sftp ServerJun 17, 2026 Oct 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authori...Show more |
Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password...Show more |
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. |
1Redhat 6Keycloak Openshift Container PlatformOpenshift Container Platform For Linuxone+3 moreJun 17, 2026 Sep 20, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more |
Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the...Show more |
1Chinamobile 1Intelligent Home Gateway Firmware Jun 17, 2026 Sep 5, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. |