failure to invalidate session on password change
N
Nextcloud
Submitted None
Actions:
Reported by
pradeepch99
Vulnerability Details
Technical details and impact analysis
Steps to reproduce
1. Login as user1 in firefox browser
2. Go to http://localhost/nextcloud/index.php/settings/personal
3. Go to other browser (chrome) and login as user1
4. Change the password in chrome
Observe that the session in firefox still works
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Authentication - Generic