Invalidate session after password reset on https://polldaddy.com
A
Automattic
Submitted None
Actions:
Reported by
nullsaint
Vulnerability Details
Technical details and impact analysis
Hi there,
I found broken session bug on your website.Your website is unable to validate the session.That may lead takeover victims account.
Reproduce:
1.Go to https://polldaddy.com and log into your account from two different browsers.
2.Now change password from any browser you already logged in
3.You will be still logged into another browser.
Kindly fix this issue.
Thx,
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Insufficient Session Expiration