Skip to content
Grav 2.0 is officially stable. Read the announcement →
Support

Session Cookie issue

Started by Benoît Barnéoud 6 years ago · 0 replies · 494 views
6 years ago

Hello!

We are working on a Grav CMS based web site for one of our client. The client IT has run pentests on our website before allowing it to be live. Unfortunately, our website didn’t successfully passed the pentests because mainly of a GRAV session fixation issue : « The application differentiates users by issuing a session cookie with a unique value. Unfortunately, the application does not issue a new session cookie and value to the user after a successful login. Instead, the user is forced to use the (old) session cookie issued before authentication. » The IT recommandation is to « invalidate any already existing session cookie when a user has logged-in. Further, make sure a new session cookie is assigned to the user after a successful authentication attempt is made in order to avoid session fixation attacks. ».

Is there any mean to correct the issue without hacking GRAV core? Indeed, we don’t want to loose further updates.

Thank you for your help!

Benoît

Suggested topics

Topic Participants Replies Views Activity
Support · by Duc , 3 hours ago
1 23 3 hours ago
Support · by Thomas, 1 week ago
3 102 12 hours ago
Support · by Anna, 3 days ago
2 99 1 day ago
Support · by Justin Young, 1 day ago
1 66 1 day ago
Support · by Duc , 1 week ago
2 101 6 days ago