Lucene search

K
huntr0xcyberyD27D232B-2578-4B32-B3B4-74AABDADF629
HistoryAug 16, 2022 - 8:12 a.m.

Insufficient Session Expiration

2022-08-1608:12:42
0xcybery
www.huntr.dev
8
session expiration
authorization
bug bounty

EPSS

0

Percentile

12.8%

Description

Insufficient Session Expiration is when a website permits an attacker to reuse old session credentials or session IDs for authorization.

Proof of Concept

Steps to reproduce
1- Login into http://127.0.0.1:5000/login/ (OctoPrint).
2- Open browser in the incognito tab or open another browser and login with the same user.
3- In step 1 change the password and login again.
4- In step 2 the old session is still valid, it must expire. 

EPSS

0

Percentile

12.8%

Related for D27D232B-2578-4B32-B3B4-74AABDADF629