logo

014 Insecure functionality


Description

A functionality that is part of the system can be leveraged by an attacker in order to negatively impact it.


Impact

Change the password after the security code has been compromised.


Recommendation

Validate on the server side that the answers to the questions are correct.


Threat

Any customer of the organization authorized from the Internet.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: H
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): N
  • Integrity (VI): L
  • Availability (VA): L
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/09/14