CWE-613
Overview
- CWE ID
- 613
- CWE Name
- Insufficient Session Expiration
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Incomplete
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."