Vulnerability Report 01: Failure to invalidate session on Email Change

Hi team,
 
I am a security researcher and this time I found this vulnerability in your website.
 
Vulnerability Report : Failure to invalidate session on Email Change
 
Weakness : Insufficient Session Expiration
 
Description: 
 
I observe that when we change Email from one browser in place of session
Expire from another browser it just updates Email from another browser and
the old session gets updated without being logged out.
 
Steps to check Session Management issue On Email change :
 
1- login From two browser at a time [ From Chrome browser and From Mozilla
Firefox ]
2- Change Email in setting from chrome browser
3- Now Check Mozilla FireFox
4- Your Session Got Updated in place of expiration
 
Recommendations:
 
If Session is Updating From One Browser so Others Should Expire First to
renew session after login.
 
Please let me know if any more info is needed !     
 
Looking after your response.
 
Thanks & Regards,
Through Star jet Cyber,
Afshan

by "starjet cyber" <starjetcyber22@gmail.com> - 10:19 - 12 Aug 2024