Session not expired When logout [partners.uber.com]
None
Vulnerability Details
Hi,
Summary
=========
partners.uber.com website is not expiring the user's session immediately after logout.
when user logout, the session not expired, and still can send request and the server respond response with OKAY
__Steps to Reproduce:__
- Log into the website - partners.uber.com
- Capture any request. For ex, profile edit page using burp proxy.
- Logout from the website.
- Replay the request captured in step 2 and notice it displays the proper response.
Thanks,
tell me if you need video, i will create one !
Actions
View on HackerOneReport Stats
- Report ID: 231041
- State: Closed
- Substate: not-applicable
- Upvotes: 12