Security Missconfiguration in Autologin

Disclosed: 2015-08-14 23:33:44 By d1pakda5 To zendesk
Unknown
Vulnerability Details
Here I am addressing Critical misconfiguration in autologin feature 1. Open the link in the browser https://dashboard.zopim.com/#home and enter your username and password and don't tick (select) the option Always sign in automatically and login 2. now logout from your account 3. now you logged out again reload the page https://dashboard.zopim.com/#home and you will be logged in here the user does not selected the autologin option but still he./she logged in automatically attack scenario lets a user is using his account on local computer so he doesnot selected the autologin option while login then his work finished and signout and left after that any one can reload the link and login his/her account Regards Dipak
Actions
View on HackerOne
Report Stats
  • Report ID: 75936
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report