Session Does Not Expire On Password Reset

Paras Arora
1 min readNov 21, 2019

--

So Here’s my short writeup on this.

To test this follow the steps:

  1. Signup for an account on a website you want to test.
  2. Login with the same account in two browsers simultaneously.
  3. Change the password of the account from any one browser.
  4. If the vulnerability exists then the account will not be logged out from another browser.

Now, you have account logged in with two browsers one with the changed password and other with the old password.

It means that session of account containing the old password does not expire.

--

--

Paras Arora
Paras Arora

Written by Paras Arora

Social media: @parasarora06 , Penetration Tester | Application Security

No responses yet