Vulnerability library
Security checkMay 13, 2024

Session Cookie without SameSite Flag

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The absence of the SameSite flag in session cookies leaves them vulnerable to cross-site request forgery (CSRF) attacks, where unauthorized actions are performed on behalf of a user. Without the SameSite flag, session cookies are susceptible to being included in cross-origin requests, potentially leading to CSRF exploits.

Recommendation

To enhance security, always set the SameSite flag for session cookies, specifying the appropriate value based on the application’s requirements. This helps prevent unauthorized access to cookies and protects against CSRF attacks by restricting their inclusion in cross-origin requests.

References

Could your website be exposed too?

SmartScanner can check your website for Session Cookie without SameSite Flag and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 13, 2024