Complimentary 90-day, on-prem license available for entities involved in Covid19 response.
Summary

Netsparker identified a user controllable cookie.

Impact

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation

Add integrity checks and server side validation to detect tampering.

Classifications
CWE-20, ISO27001-A.14.2.5, WASC-20
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Tags

cookie 
Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO