- Status Closed
-
Assigned To
cbay - Private
Opened by waloodi_109 - 15.10.2025
Last edited by cbay - 16.10.2025
FS#223 - Failure to invalidate session after logout from 2nd tab
#Failure to invalidate session after logout from 2nd tab.
Hello Team,
I hope you are doing well. While Researching in your domain I found Failure to invalidate session after logout from 2nd tab vulnerability in your domain. Attacker can view token and any sensitive data.
This Vulnerability found in:
1. admin.alwaysdata.com
2. webmail.alwaysdata.com
#Steps to Reproduce:
1. Login to admin.alwaysdata.com
2. Open another tab and copy the login account URL and paste into 2nd tab.
3. Go to profile option into 1st tab or any other sensitive data page.
4. Logout your account from 2nd tab and then visit to 1st tab, don't refresh that page, so you can see that page is still active and attacker can see victim details or any sensitive data.
Impact:
If a user login their account in café or in a office, Victim open another tab for doing their work and then logout the account in that tab. Victim assume that the account are logged out and victim forget to close the browser but into 1st tab, victim account are still logged in and attacker can view any sensitive data and token or any bank details.
#Note:
I can make a one video for both('admin.alwaysdata.com','webmail.alwaysdata.com')
Thank You,
Waleed Anwar
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Any Update Sir?
Hello,
That's completely standard web behaviour.
Kind regards,
Cyril
I tested this in LinkedIn and different websites, there session are directly terminated if i logout from second tab