Session not expired when password has been changed [app.cobalt.io]

Session not expired when password has been changed on app.cobalt.io

Description

When user change password from another platform, the previous platform still connect to account and still can edit the profile.

POC :

1. Login on mozilla,
2. Login on Chrome,
3. change the password on chrome.
4. back to mozilla, you still able to access the account
5. you still can edit profile.

Video : 

https://youtu.be/Cz2zh7w4n6M (unlisted )

Bounty :



Note : I ask permission to app.cobalt.io to write it on my blog, and them give me the permission, so I write here,

Hope you enjoy~

Comments

Popular posts from this blog

Missing CSRF Token On Add Admin [Popoji CMS]

Session not expired When logout [partners.uber.com]

Open Redirect On Codepolitan.com