Old Sessions remain valid after the password change.

Disclosed: 2014-06-11 08:54:02 By siddiki To relateiq
Unknown
Vulnerability Details
**Industry Standard Procedure** When the password is changed or email address has been updated for any particular account,all the sessions which were active with the old password/email should be destroyed. **Reason** If somehow anybody hacked into your account and you understand that someone has trespassed into your account,then what will you do?You will change your password to secure your account.But in relateIQ changing the password doesnot destroys the other sessions which are logged in with old passwords.So,your account remains insecure even after the changing of password.
Actions
View on HackerOne
Report Stats
  • Report ID: 10186
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report