User Controllable Cookie
Summary#
Invicti identified a user controllable cookie.
Impact#
Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.
Remediation#
Add integrity checks and server side validation to detect tampering.
Classifications#
Invicti Security Insights