All Projects

ID Status Summary Opened by
 506 Closed Webmail session remains authenticated after logout (ses ...parthsolankih9 Task Description

Severity suggestion: Medium

Affected service: https://webmail.alwaysdata.com (exact in-scope hostname)

Description

After a user logs out of the webmail (?_task=logout, the link the UI itself offers: ./?_task=logout), the platform session cookie remains fully authenticated. A subsequent request to /roundcube/?_task=mail returns the user's live inbox without any re-authentication, and a request to the webmail root (/) immediately redirects back to /roundcube/?_task=mail — the proxy layer re-establishes the Roundcube session from its stored state. Logging out therefore does not end the session.

Steps to reproduce (standard Linux tools only, per program guidelines)

1. GET https://webmail.alwaysdata.com/ — obtain CSRF cookie and csrfmiddlewaretoken.
2. POST https://webmail.alwaysdata.com/ with csrfmiddlewaretoken, login=<mailbox>, password=<password> → 302 to /roundcube/?_task=mail; a platform session cookie is set.
3. GET /roundcube/?_task=mail&_mbox=INBOX → 200, <title>webmail :: Inbox</title> (pre-logout confirmation).
4. GET /roundcube/?_task=logout → 200 logout page (request is processed).
5. GET /roundcube/?_task=mail&_mbox=INBOX with Cache-Control: no-cache → 200, <title>webmail :: Inbox</title>, fully authenticated mailbox view.
6. GET https://webmail.alwaysdata.com/ → 302 back to /roundcube/?_task=mail — session re-established automatically.

Steps 5–6 reproduced on a fresh session, twice (initial observation plus a controlled retest), with cache-busting headers — this is not a cached-page artifact.

Impact

- A user who logs out on a shared or compromised machine believes their mail session has ended. Any party who captured the session cookie retains full mailbox access indefinitely — the standard mitigation ("log out") does not invalidate the credential.
- The mailbox receives alwaysdata's own password-reset and account emails, so persistent mailbox access also means persistent reachability into the account-recovery flow of the platform.

Test account note

Testing was performed with a dedicated test account that I own and control; I can re-verify against a patched build on request. (Please keep this report free of the test credentials — happy to share them privately if useful for triage.)

Showing tasks 1 - 1 of 1 Page 1 of 1

Available keyboard shortcuts

Tasklist

Task Details

Task Editing