Vulnerabilities > Reliance on Cookies without Validation and Integrity Checking

DATE CVE VULNERABILITY TITLE RISK
2024-10-15 CVE-2024-9820 Reliance on Cookies without Validation and Integrity Checking vulnerability in Dueclic WP 2FA With Telegram
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0.
network
low complexity
dueclic CWE-565
7.5
2024-07-14 CVE-2024-39734 Reliance on Cookies without Validation and Integrity Checking vulnerability in IBM Datacap
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-565
4.3
2023-12-18 CVE-2023-32725 Reliance on Cookies without Validation and Integrity Checking vulnerability in Zabbix Frontend and Zabbix Server
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports.
network
low complexity
zabbix CWE-565
8.8
2023-10-16 CVE-2023-45141 Reliance on Cookies without Validation and Integrity Checking vulnerability in Gofiber Fiber
Fiber is an express inspired web framework written in Go.
network
low complexity
gofiber CWE-565
8.8
2023-09-18 CVE-2023-41084 Reliance on Cookies without Validation and Integrity Checking vulnerability in Socomec Modulys GP Firmware 01.12.10
Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.
network
low complexity
socomec CWE-565
critical
9.8
2023-09-07 CVE-2023-3747 Reliance on Cookies without Validation and Integrity Checking vulnerability in Cloudflare Warp 6.29
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices.
local
low complexity
cloudflare CWE-565
5.5
2023-06-20 CVE-2023-35885 Reliance on Cookies without Validation and Integrity Checking vulnerability in Mgt-Commerce Cloudpanel
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
network
low complexity
mgt-commerce CWE-565
critical
9.8
2023-06-13 CVE-2023-3050 Reliance on Cookies without Validation and Integrity Checking vulnerability in Tmtmakine Lockcell Firmware
Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15.
network
low complexity
tmtmakine CWE-565
critical
9.8
2023-02-01 CVE-2022-3083 Reliance on Cookies without Validation and Integrity Checking vulnerability in Landisgyr E850 Firmware
All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie.
network
low complexity
landisgyr CWE-565
5.4
2022-08-12 CVE-2022-2615 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject CWE-565
6.5