Burp Suite User Forum

Create new post

SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE

Spark | Last updated: Oct 04, 2021 04:33PM UTC

Description: On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active STEPS TO REPRODUCE: 1. Log in to Browser A and make sure to check 'stay logged in to this device' checkbox while logging in. 2.From Browser B login to your account and change password Notice that Session on Browser A will remain active and does not expire. IMPACT: Due to this bug, there is no way for the victim to revoke access of attacker if account has been already compromised

Ben, PortSwigger Agent | Last updated: Oct 05, 2021 07:41AM UTC

Hi Omkar, As noted in your earlier email - please submit in-scope bug reports using the links provided below: https://portswigger.net/blog/portswigger-bug-bounty-program Cheers Ben Wright Technical Product Specialist PortSwigger

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.