Loading HuntDB...

Invalidate session after password reset on https://polldaddy.com

A
Automattic
Submitted None
Reported by nullsaint

Vulnerability Details

Technical details and impact analysis

Insufficient Session Expiration
Hi there, I found broken session bug on your website.Your website is unable to validate the session.That may lead takeover victims account. Reproduce: 1.Go to https://polldaddy.com and log into your account from two different browsers. 2.Now change password from any browser you already logged in 3.You will be still logged into another browser. Kindly fix this issue. Thx,

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Insufficient Session Expiration