rspec/rules/S5328/description.adoc
2020-06-30 17:16:12 +02:00

2 lines
176 B
Plaintext

If a session ID can be guessed (not generated with a secure pseudo random generator, or with insufficient length ...) an attacker may be able to hijack another user's session.