By exploiting one or several application vulnerabilities it is possible to take control over a user account and perform action on his behalf
- Affect the traceability and non-repudiation of the user's actions.
- Deny the access of a legitimate user to its own account
- Obtain potentially confidential information from the user account
Define account recovery mechanisms, validating that the requester is the account owner.
Authenticated attacker from the Internet
Expected Remediation Time
Default score using CVSS 3.1. It may change depending on the context of the src.
- Attack vector: N
- Attack complexity: H
- Privileges required: L
- User interaction: N
- Scope: U
- Confidentiality: L
- Integrity: L
- Availability: L
- Exploit code madurity: H
- Remediation level: U
- Report confidence: C
- Vector string: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:H/RL:U/RC:C
- Base: 5.0
- Temporal: 5.0
- Base: Medium
- Temporal: Medium
Search for vulnerabilities in your apps for free with our automated security testing! Start your 21-day free trial and discover the benefits of our Continuous Hacking Machine Plan. If you prefer a full service that includes the expertise of our ethical hackers, don't hesitate to contact us for our Continuous Hacking Squad Plan.