Session is not invalidated on password change --> https://my.zapinfo.io

Disclosed by
h_-_cker
  • Program Indeed
  • Disclosed date over 1 year ago
  • Reward $100
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by h_-_cker

This session management vulnerability was found when Zapinfo platform was also supporting its own set of credentials instead of Indeed credentials only. The program's team is very professional to accept the issues when there's impact. It was resolved through parallel & independent changes to the application's authentication workflow.

Activity