Session Fixation At Logout /Session Misconfiguration
None
G
Gratipay
Submitted None
Actions:
Reported by
aa23
Vulnerability Details
Technical details and impact analysis
Dear Suppport Team ,
Commonly After Logout time , session should destroy and then new session should be created ..
But in your application , it is not possible and same sessioncookie is there before logout and after logout from your application . For further details please find the attachment....
Ragards,
a23
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Authentication - Generic