CAPEC-21: Exploitation of Trusted Identifiers
An adversary guesses, obtains, or "rides" a trusted identifier (e.g. session ID, resource ID, cookie, etc.) to perform authorized actions under the guise of an authenticated user or service.
Severity
High
Likelihood
High
5
/ 100
low-risk
Active Threat
5/50 · Minimal
Exploit Availability
0/50 · Minimal