Sceawere
Vulnerability Detail
CVE-2026-105233UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Session Fixation in Login Flow
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 12h ago
- Vendor
- kishor-23
- Product
- food-waste-management-system
- Attack Type
- Session Fixiation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation of the argument PHPSESSID leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T06:16:57.803Z",
"pubdate": "2026-10-05T06:16:57.803Z",
"executiveSummary": "A session fixation vulnerability exists in the login.php component of the kishor-23 food-waste-management-system (commit 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c).\nThe vulnerability arises due to the application's failure to regenerate the session identifier upon successful authentication, allowing an attacker to fixate a known PHPSESSID for a victim user.\nSuccessful exploitation permits unauthorized access to a victim's session, leading to full account takeover, unauthorized data access, and potential manipulation of system functions.\nThis vulnerability is remotely exploitable and does not require complex preconditions beyond the attacker obtaining or setting a session ID on the victim's browser.\nThe risk is critical as the project lacks versioning and has remained unresponsive to disclosure reports, leaving current implementations exposed.",
"technicalDetails": "The vulnerability resides within the session management mechanism of the login.php file in the Login Flow component. The root cause is the improper handling of the session lifecycle, specifically the failure to rotate or regenerate the session token (PHPSESSID) during the transition from an unauthenticated state to an authenticated state.\nIn a secure implementation, an application must call session_regenerate_id(true) immediately upon verifying user credentials. This ensures that the session ID associated with the anonymous session is invalidated and replaced by a new, cryptographically strong identifier for the authenticated session. The absence of this call in the subject system allows for a fixation attack vector.\nThe attack flow follows these steps: 1. The attacker accesses the target application and obtains a legitimate session identifier (e.g., PHPSESSID=attacker_id) provided by the server. 2. The attacker uses various social engineering or cross-site scripting (XSS) vectors to force the victim's browser to adopt this specific PHPSESSID, effectively 'fixating' the session. 3. The victim visits the login page using the browser configured with the attacker's fixed session ID. 4. The victim provides legitimate credentials. 5. Because the application fails to regenerate the session ID upon login, the victim's authenticated state is now associated with the session ID known to the attacker. 6. The attacker uses the fixed PHPSESSID to gain unauthorized access to the application as the victim, bypassing the authentication mechanism entirely.\nThis vulnerability is classified as a session fixation attack because the attacker pre-defines the session ID that will be used by the victim. Because the application logic does not distinguish between an anonymous session and an authenticated session during the upgrade process, the persistent PHPSESSID maintains the context of the user after they have successfully logged in.\nThe impact is significant, as it enables account impersonation without requiring the victim's actual password. An attacker can perform any action available to the victim user, such as managing food waste data or modifying administrative settings, depending on the victim's privilege level. This is a purely server-side logic flaw that requires no special privileges to initiate, provided the attacker can influence the victim's session cookie."
}