Failure to Invalid Session after Password Change

Disclosed by
VIVEK_PANDAY
  • Engagement ISC2
  • Disclosed date over 5 years ago
  • Points 1
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Unresolved This vulnerability has been accepted and needs to be fixed
Summary by VIVEK_PANDAY

Summary:

While conducting my researching I discovered that the application Failure to invalidate session after changing the password doesn't destroys the other sessions which are logged in with old passwords.

Steps To Reproduce:

1) Open same accounts in two different browsers
2) Change password in one browser and you will see that another browser still validate the session after password change (even after refresh the page ).

Activity