Insufficient Session Expiration in forkcms/forkcms
Valid
Reported on
Oct 14th 2021
Description
Insufficient Session expiration even after Credential like password of the account is being updated.
Proof of Concept
- open the same account in multiple browsers.
- change the password in one Browser.
- Reload the other one.
- as a result we can see the account on the other browser is not being logged out.
Impact
The session persists even after password change
We have contacted a member of the
forkcms
team and are waiting to hear back
2 years ago
to join this conversation