Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.
https://github.com/symphonycms/symphony-2/commit/b329a14adc40868965076a77210452e396243dcd
http://www.securityfocus.com/bid/91299
http://www.securityfocus.com/archive/1/538714/100/0/threaded
http://hyp3rlinx.altervista.org/advisories/SYMPHONY-CMS-SESSION-FIXATION.txt
Source: Mitre, NVD
Published: 2016-06-30
Updated: 2026-05-06
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.12598