The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE

Spark | Last updated: Oct 04, 2021 04:33PM UTC

Description: On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active STEPS TO REPRODUCE: 1. Log in to Browser A and make sure to check 'stay logged in to this device' checkbox while logging in. 2.From Browser B login to your account and change password Notice that Session on Browser A will remain active and does not expire. IMPACT: Due to this bug, there is no way for the victim to revoke access of attacker if account has been already compromised

Ben, PortSwigger Agent | Last updated: Oct 05, 2021 07:41AM UTC