Session is not expire after logout

Disclosed: 2019-11-08 13:12:23 By saqib98 To owox
Medium
Vulnerability Details
Reproduction: step no 1:Open URL:https://www.owox.com/products/ or open your user account step no 2: copy URL or paste another tab step no 3:Go back again first tab or logout your account step no 4: And check the copied URL section is working properly Reference From :#244875 Reference From :#263873 Reference From :#249798 Hope you fix this soon ;) Best Regards, SAQIB_ARIF ## Impact An attacker can get the user's session cookies by using Session Spoofer, Cookie Staler, etc. and thus, can get access to the user account. Perform action: Changes profile Delete account
Actions
View on HackerOne
Report Stats
  • Report ID: 709378
  • State: Closed
  • Substate: resolved
  • Upvotes: 16
Share this report