logo

Database

Authentication mechanism absence or evasion - Security Image

Description

It is possible to eliminate the use of the image and security phrase at user login.

Impact

Remove image and security phrase which can facilitate other types of attacks.

Recommendation

Make sure that only one number of an existing image can be sent so that the image and passphrase function is not eliminated.

Threat

User authenticated from the Internet.

Expected Remediation Time

⏱️ 240 minutes.

Fixes