Old session tokens can be used to authenticate to the application and send authenticated requests.
{ "cwe_ids": [ "CWE-613" ] }