CAPEC-21: Exploitation of Trusted Identifiers

An adversary guesses, obtains, or "rides" a trusted identifier (e.g. session ID, resource ID, cookie, etc.) to perform authorized actions under the guise of an authenticated user or service.

Severity
High
Likelihood
High
5
/ 100
low-risk
Active Threat 5/50 · Minimal
Exploit Availability 0/50 · Minimal