You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
According to WASC, Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.
Learn more on MITRE.
Impact
Deleted/deactivated user could continue to use his account as long as its cookie is valid
Patches
Upgrade to 10.0.4.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].