Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users

A flaw in a custom session-cookie system allowed an unauthenticated attacker to pose as employees and administrators in a yard management platform. The issue did not break Microsoft Entra ID itself. Instead, it let a weak application-side session layer accept a forged identity after the normal sign-in controls had been bypassed. The affected platform used […]

This article has been indexed from Cyber Security News

Read the original article: