User Controllable Cookie

Severity: Low
Summary#

Invicti identified a user controllable cookie.

Impact#

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation#

Add integrity checks and server side validation to detect tampering.

Classifications#
OR

Search Vulnerability

Tags

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works