Invalidate session after password reset on https://polldaddy.com

Disclosed: 2017-11-09 13:11:40 By nullsaint To automattic
Unknown
Vulnerability Details
Hi there, I found broken session bug on your website.Your website is unable to validate the session.That may lead takeover victims account. Reproduce: 1.Go to https://polldaddy.com and log into your account from two different browsers. 2.Now change password from any browser you already logged in 3.You will be still logged into another browser. Kindly fix this issue. Thx,
Actions
View on HackerOne
Report Stats
  • Report ID: 273881
  • State: Closed
  • Substate: informative
  • Upvotes: 11
Share this report