Base solution for your next web application
Open Closed

Insecure Session Management #12554


User avatar
0
kansoftware created

I am copying the cookies from Browser A (admin user) and replacing them in Browser B (normal user) leads to the normal user session being converted to an admin session—is a security vulnerability related to session management.

Please find the attached images.

An attacker who can set or inject a valid session cookie into a victim's browser can impersonate that account, access sensitive data, and perform fully compromises user sessions (including admin account).

Could you kindly assist us in resolving the security vulnerability mentioned above?

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

3 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @kansoftware

    Thank you for your feedback. I've created an issue for this. You can follow the developments here. Thank you.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    Hi, when can we expect a solution for the above issues?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @kansoftware

    This issue has been included in the 15.1 milestone. After the 15.0 version is released soon, it is planned to be resolved in version 15.1.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)