Cookie Session Not Expiring Even After Deleting the users in pyload/pyload
Valid
Reported on
Jan 5th 2023
Description
The session is not expiring in another browser if we delete the user.
Proof of Concept
- Create two users with an admin role for the POC
- Login in two different browsers Firefox (user A ) and Chrome (user B) respectively
- Go the settings->users and delete user B from user A Firefox browser
- User B cookie is still logged in in Chrome and can still access everything
Impact
Even after deleting the user he/she can create again the user for himself/herself, and can perform everything.
We are processing your report and will contact the
pyload
team within 24 hours.
3 months ago
We have contacted a member of the
pyload
team and are waiting to hear back
3 months ago
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability has been assigned a CVE
to join this conversation