Is it possible for a malicious user to edit $_SESSION?

后端 未结 7 796
抹茶落季
抹茶落季 2020-12-16 00:02

I save some important info in $_SESSION, not in $_COOKIE. So, my question, is it dangerous? Or is it protected from malicious users trying to edit

7条回答
  •  别那么骄傲
    2020-12-16 00:21

    Cookies are sent via the user-agent every time a page is requested. The user-agent doesn't need to be a browser. It could be a small shell script. Even if it is a browser, there's an "edit cookie" extension for Firefox.

提交回复
热议问题