Summary

Acunetix 360 identified a user controllable cookie.

Impact

Attackers can easily set an arbitrary value in the cookie and this may allow them to bypass authentication, carry out attacks such as SQL injection and cross-site scripting or modify inputs in unexpected ways.

Remediation

Add integrity checks and server side validation to detect tampering.

Severity

Low

Classification

CWE-20 ISO27001-A.14.2.5 WASC-20