Summary #

Netsparker identified a user controllable cookie.

Impact #

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation #

Add integrity checks and server side validation to detect tampering.

Classifications #
CWE-20, ISO27001-A.14.2.5, WASC-20
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Tags

cookie 
Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO