Skip to main content

Unauthorized access to screen

Description

An advisor, through the GLIA application, should not have access to client information. However, the advisor can obtain different client data (without the client being aware of it), simply by logging into the user window and following the flow that the user goes through when opening an account.

Impact

Obtain confidential information from users without their approval.

Recommendation

User information should not be exposed to a third party in any part of the account opening flow.

Threat

Attacker from the Internet with access to GLIA application.

Expected Remediation Time

⌚ 120 minutes.

Score

Default score using CVSS 3.1. It may change depending on the context of the vulnerability.

Base

  • Attack vector: N
  • Attack complexity: L
  • Privileges required: L
  • User interaction: R
  • Scope: U
  • Confidentiality: L
  • Integrity: N
  • Availability: N

Temporal

  • Exploit code madurity: X
  • Remediation level: X
  • Report confidence: X

Result

  • Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
  • Score:
    • Base: 3.5
    • Temporal: 3.5
  • Severity:
    • Base: Low
    • Temporal: Low

Code Examples

Compliant code

User sensitive information is only accesible to an identifiable authorized user

Non compliant code

The application shows user sensitive information in the registration process without using some form of secure id validation

Requirements

free trial

Search for vulnerabilities in your apps for free with our automated security testing! Start your 21-day free trial and discover the benefits of our Continuous Hacking Machine Plan. If you prefer a full service that includes the expertise of our ethical hackers, don't hesitate to contact us for our Continuous Hacking Squad Plan.