DOM based XSS in the field query
i4
To be prioritized
User account theft using authentication delegation
i4
To be prioritized - Also to decide if we want to have an ‘Account verification process’ to validate the account
Automatic user enumeration possible
i4
Netace should prevent this problem (but only ES + PT)
Arbitrary method request do not send a 405 error
Teradisk
Disclosure version in the HTTP responses
Teradisk
HTTP headers Content Security Policy missing
i4
Potentially outdated nginx version
Teradisk
Session timeout too long
Atida
For business reasons we prefer to keep a long session
The system of double submit cookie is not completely secure
i4
To be prioritized