Analysis:
During the analysis, it was observed that multiple logins for the same user from different systems/browsers were allowed. Please refer to the below-provided evidence:
Impact:
An attacker who has compromised the credentials of a user may login from another computer using these credentials. If simultaneous logins are disallowed, such an action would alert the genuine user of the application to misuse his/her credentials.
Recommendation:
It is recommended that when a user logged into an application, the user should not be permitted to open a different type of browser (or use another computer) to log in again until his first session has ended.
Comments
Post a Comment