Summary

Netsparker identified a user controllable cookie.

Impact

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation

Add integrity checks and server side validation to detect tampering.

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO