Session Fixation in bytebase/bytebase
Valid
Reported on
Oct 13th 2021
Description
If admin deciding to deactivate a user and the user already logged in the system before then until user remain in the current session he/she can do anything that can do them before.