# VAPT errors and how to fix them?

**URL:** <https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239>\
**Category:** Uncategorized\
**Created:** [August 12, 2025, 1:03pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239 "2025-08-12T13:03:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cryptospy](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/cryptospy/32/1169_2.png) [@Cryptospy](https://discourse.getcockpit.com/u/Cryptospy)\
**Post date:** [August 12, 2025, 1:03pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/1 "2025-08-12T13:03:36Z")

</div>

i am in 7-8 month older version of cockpit, but ondoing Vulnerability Assessment and Penetration Testing by my client, they found

1. PII Disclosure

2. stored xss and xss through file upload ,

3. CSRF Token Reuse,

4. Authentication Bypass via Response Manipulation

5. Session Hijacking,

Note it was a plain installation , with little to no customization.

---

<div class="post-metadata">

**Author:** ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)\
**Post date:** [August 13, 2025, 4:21pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/2 "2025-08-13T16:21:09Z")

</div>

which version are you on?

---

<div class="post-metadata">

**Author:** ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)\
**Post date:** [August 13, 2025, 4:26pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/3 "2025-08-13T16:26:17Z")

</div>

It would also make sense the share the findings privately or do an assessment in general against a newer version

---

<div class="post-metadata">

**Author:** ![Cryptospy](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/cryptospy/32/1169_2.png) [@Cryptospy](https://discourse.getcockpit.com/u/Cryptospy)\
**Post date:** [August 16, 2025, 11:52am UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/4 "2025-08-16T11:52:11Z")

</div>

okay i am sending you the reports today

---

<div class="post-metadata">

**Author:** ![HelloDolly](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hellodolly/32/1181_2.png) [@HelloDolly](https://discourse.getcockpit.com/u/HelloDolly)\
**Post date:** [November 10, 2025, 1:23pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/5 "2025-11-10T13:23:11Z")

</div>

did you find solution?

---

<div class="post-metadata">

**Author:** ![HelloDolly](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hellodolly/32/1181_2.png) [@HelloDolly](https://discourse.getcockpit.com/u/HelloDolly)\
**Post date:** [November 10, 2025, 1:32pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/6 "2025-11-10T13:32:29Z")

</div>

based on his we did a test on our internal framework built on top of urs

Token Reuse is indeed valid:

 ![1](https://canada1.discourse-cdn.com/flex030/uploads/getcockpit/original/2X/9/96052ecf93aaa65d01fa3224e5c02b828d119f54.png)  
 ![2](https://canada1.discourse-cdn.com/flex030/uploads/getcockpit/original/2X/0/0363d103e46d975a08a4e2cd5549e6c1ccd59199.png)

---

<div class="post-metadata">

**Author:** ![HelloDolly](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hellodolly/32/1181_2.png) [@HelloDolly](https://discourse.getcockpit.com/u/HelloDolly)\
**Post date:** [November 10, 2025, 1:36pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/7 "2025-11-10T13:36:17Z")

</div>

i was able to replicate session hijacking too using cookie editor:  
steps:  
login to cockpit-\> export session cookie using cookie editor extension → import cookie in a different device using the same extension-\> login boom 😟

 ![image](https://canada1.discourse-cdn.com/flex030/uploads/getcockpit/original/2X/4/44f552c6cdf764f633ed8001bdf94e4327080163.jpeg)  
 ![image](https://canada1.discourse-cdn.com/flex030/uploads/getcockpit/original/2X/b/b4c02b013380535979ea6f581a286d446bab24ae.png)

---

<div class="post-metadata">

**Author:** ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)\
**Post date:** [November 12, 2025, 10:29pm UTC](https://discourse.getcockpit.com/t/vapt-errors-and-how-to-fix-them/3239/8 "2025-11-12T22:29:31Z")

</div>

This is a php.ini configuration issue. Make sure to have the following configured:

```  
session.cookie\_httponly = 1  
session.cookie\_secure = 1  
session.cookie\_samesite = “Strict”  
session.use\_only\_cookies = 1  
session.use\_strict\_mode = 1

```
