CWE-784: Reliance on Cookies without Validation and Integrity Checking in a Security Decision

VariantDraftExploit Likelihood: High

The product uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.

View on MITRE
Back to CWE Lookup

Extended Description

Attackers can easily modify cookies, within the browser or by implementing the client-side code outside of the browser. Attackers can bypass protection mechanisms such as authorization and authentication by modifying the cookie to contain an expected value.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More