Session Fixation
Vulnerability Description
The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25977
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Florian Stuhlmann, Thorger Jansen (Office Bochum) | SEC Consult Vulnerability Lab
References
More from Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany
View All →Affected Vendor
Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany
View all reports →