CAPEC-593: Session Hijacking

This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.

Severity
Very High
Likelihood
High
17
/ 100
low-risk
Active Threat 14/50 · Low
Exploit Availability 3/50 · Minimal