Cookies are not cleared from Server side on Logout
M
Mavenlink
Submitted None
Actions:
Reported by
rajauzairabdullah
Vulnerability Details
Technical details and impact analysis
i logged out from my account after using it and then clicked on back i found my account logged in.Cookies are not handled well on logged out.I saw that cookie is not expired. If the hacker gets victim's cookie, the hacker can use it for a pretty good time period.
Best Regardz
RajaUzairAbdullah
@UzaiRaja
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate