AttackFlow Findings Dictionary

Insecure Legacy Forms Authentication

The attackers can login into the application as other users



Fix Cost


Trust Level


ASP.NET Forms Authentication mechanism has a vulnerability that allows attackers to send unvalidated inputs when registering into the applications and then logging as other users.

On newer ASP.NET versions the vunerability is patched by changing input validation strategies, however, the existence of a legacy directive below will revert back the fixed mechanism to unfixed one.

<add key="aspnet:UseLegacyFormsAuthenticationTicketCompatibility" value="true" />

