9. of Tampering II
An attacker can provide or control state information:
Threat |
|
You’re accepting session IDs in Once your users are authenticated, the attacker is then able to hijack the users’ sessions and gain access to your systems. |
|
CAPEC |
CAPEC-61: Session Fixation CAPEC-593: Session Hijacking |
ASVS |
3.2.1: Ensure that a new session is created on login |
CWE |
CWE-384: Session Fixation |
Mitigations |