CWE-302: Authentication Bypass by Assumed-Immutable Data
BaseIncomplete
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
View on MITREBack to CWE Lookup
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific