Burp Suite User Forum

Create new post

SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE

Spark | Last updated: Oct 04, 2021 04:33PM UTC

Description: On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active STEPS TO REPRODUCE: 1. Log in to Browser A and make sure to check 'stay logged in to this device' checkbox while logging in. 2.From Browser B login to your account and change password Notice that Session on Browser A will remain active and does not expire. IMPACT: Due to this bug, there is no way for the victim to revoke access of attacker if account has been already compromised

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.