PHP Can a client ever set $_SESSION variables?

后端 未结 4 968
谎友^
谎友^ 2020-12-30 00:48

Is there any scenario where a client/user/hacker can set $_SESSION variables themselves (excluding malicious software running on a server computer. I mostly mea

4条回答
  •  小鲜肉
    小鲜肉 (楼主)
    2020-12-30 00:55

    I don't think $_SESSION variables can be changed unless the user has server access otherwise no they can't change it but filtering the variables or sanitizing it is recommended if it is something the user enters.

提交回复
热议问题