Skip to main content
ihorp86864558
Participant
March 9, 2026
Answered

Weak Session Token Randomness

  • March 9, 2026
  • 1 reply
  • 25 views

Weak Session Token Randomness vulnerability found during pentesting in ColdFusion 2023 Administrator
 

During a recent pentesting exercise, we identified a vulnerability related to Weak Session Token Randomness in ColdFusion 2023, specifically affecting the Administrator interface. Our analysis shows that only about 6 out of 80 characters in the session cookie have an acceptable level of randomness, which raises concerns about session security and potential risks.

Could you please advise if there are any configuration options or recommended best practices in ColdFusion 2023 to improve the randomness and security of session tokens for the Administrator? Is it possible to change the session ID generator or enable a more secure session management mechanism?

Any guidance or recommendations on how to mitigate this vulnerability would be greatly appreciated.

Thank you in advance for your support!

    Correct answer Ged_Traynor

    @ihorp86864558 you’d be better off posting your query in the ColdFusion forum

    1 reply

    Ged_Traynor
    Community Expert
    Ged_TraynorCommunity ExpertCorrect answer
    Community Expert
    March 11, 2026

    @ihorp86864558 you’d be better off posting your query in the ColdFusion forum