Security Missconfiguration in Autologin
Unknown
Vulnerability Details
Here I am addressing Critical misconfiguration in autologin feature
1. Open the link in the browser https://dashboard.zopim.com/#home and enter your username and password and don't tick (select) the option Always sign in automatically and login
2. now logout from your account
3. now you logged out again reload the page https://dashboard.zopim.com/#home and you will be logged in
here the user does not selected the autologin option but still he./she logged in automatically
attack scenario
lets a user is using his account on local computer so he doesnot selected the autologin option while login
then his work finished and signout and left after that any one can reload the link and login his/her account
Regards
Dipak
Actions
View on HackerOneReport Stats
- Report ID: 75936
- State: Closed
- Substate: informative
- Upvotes: 3