Broken Authentication and Sessions Management
Detailed review of authentication mechanisms to ensure that user's credentials are protected and only an authorized user can change them. Review your session management mechanism, that session identifiers are always protected.