CWE-20
ISO27001-A.14.2.5
WASC-20

User Controllable Cookie

Severity:
Low
Summary

Invicti identified a user controllable cookie.

Impact

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation

Add integrity checks and server side validation to detect tampering.

Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.