codex.one
On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active
Weakness: Insufficient Session Expiration
Impact :-
Due to this bug, there is no way for the victim to revoke access of attacker if account has been already compromised
To verify the issue :
Proof Of Bug Video Link : - https://drive.google.com/file/d/1n-cMAl7z-7ef-aULewp2asY2dHhH3uWw/view?usp=sharing