Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40415
HistoryMay 08, 2023 - 12:47 p.m.

Insufficient Session Expiration

2023-05-0812:47:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
session expiration
vulnerability
web application
reset password
browser history
security

EPSS

0

Percentile

5.1%

serenity.net.web is vulnerable to Insufficient Session Expiration. A link contains a token that could be used to reset a password, but it has a three-hour expiration date and is given as a query parameter. If the attacker has access to the browser history, they can use the token once more to obtain control of the account.

EPSS

0

Percentile

5.1%