Description

Pyramid web application can store a user's session in a cookie. For protection against cookie data tampering, Pyramid signs the session cookie value with a secret key. It's very important that an attacker doesn't know the value of this secret key. Your application is using a weak/known secret key and Acunetix managed to guess this key.

Remediation

Change the value of the secret key to a long random string.

References

Related Vulnerabilities