it is possible to test if the session token is exposed to this vulnerability and try to create a replay session attack.+When an application does not renew the cookie after a successful user authentication, it could be possible to find a session fixation vulnerability and force a user to utilize a cookie known to the attacker.<br>