Lucene search

K
huntrDhina016F3644772-9C86-4F55-A0FA-AEB11F411551
HistoryJan 30, 2023 - 9:58 a.m.

Session Fixation in https://demo.froxlor.org/

2023-01-3009:58:40
dhina016
www.huntr.dev
7
session fixation
phpsessid
login
logout
bug bounty
web application security

0.001 Low

EPSS

Percentile

32.8%

Description

The session ID not rotating even after relogin

POC

1. Change the PHPSESSID=newsessionchanged and then login
2. Use the same session into new browser and as you can see logged into the account
3. you can try logout and login again the PHPSESSID doesn't change.

Video POC: https://drive.google.com/file/d/1fvc2fWERQT-eCo9KBKKkz_-bAJSfrROR/view?usp=share_link

0.001 Low

EPSS

Percentile

32.8%

Related for F3644772-9C86-4F55-A0FA-AEB11F411551