An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does…
CERT-PL·CWE-347·Published 2025-08-27