Session not expired When logout [partners.uber.com]

Disclosed: 2017-05-26 22:56:44 By hurthearts To uber
None
Vulnerability Details
Hi, Summary ========= partners.uber.com website is not expiring the user's session immediately after logout. when user logout, the session not expired, and still can send request and the server respond response with OKAY __Steps to Reproduce:__ - Log into the website - partners.uber.com - Capture any request. For ex, profile edit page using burp proxy. - Logout from the website. - Replay the request captured in step 2 and notice it displays the proper response. Thanks, tell me if you need video, i will create one !
Actions
View on HackerOne
Report Stats
  • Report ID: 231041
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 12
Share this report