CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10. |
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an au...Show more |
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. |
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's...Show more |
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token. |
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors. |
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed. |
Silverstripe silverstripe/framework through 4.10 allows Session Fixation. |
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation. |
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 27, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. |
1Bbraun 2Datamodule Compactplus SpacecomJun 17, 2026 Apr 14, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sess...Show more |
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request. |
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session....Show more |
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inc...Show more |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Feb 2, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040. |
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session. |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session...Show more |
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access ca...Show more |
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in....Show more |