logo

Database

Description

User sessions do not expire after 5 minutes of inactivity.

Impact

- Obtain user information. - Upload files to the application without authorization.

Recommendation

Close the sessions when they remain inactive more than 5 minutes.

Threat

Anonymous attacker from local network with access to an unatended session.

Expected Remediation Time

⏱️ 60 minutes.