9. of Tampering I
An attacker can provide or control state information:
Threat |
|
You aren’t signing or securing your cookies correctly, so an attacker can modify a cookie. |
|
CAPEC |
CAPEC-31: Accessing/Intercepting/Modifying HTTP Cookies |
ASVS |
3.4 and 3.: Ensure cookies are secured properly and only accessible from the source host |
CWE |
CWE-565: Reliance on Cookies without Validation and Integrity Checking |
Mitigations |
|
|