0

I wonder what Session Fixation exploit possibilities still exist today in case the website does not change the Session-ID in a cookie after login other than the following:

  1. XSS
  2. MiTM
  3. open redirect vuln

We've encountered a customer website which has the issue and would like to design a PoC to exploit it.

schroeder
  • 123,438
  • 55
  • 284
  • 319
VJSpeter
  • 1
  • 1

0 Answers0