Exploitation of Trusted Identifiers
CAPEC-21 · Meta · Stable
An adversary guesses, obtains, or "rides" a trusted identifier (e.g. session ID, resource ID, cookie, etc.) to perform authorized actions under the guise of an authenticated user or service.
likelihood: High
severity: High