|
Task Description
Severity suggestion: Medium
Affected service: https://webmail.alwaysdata.com (exact in-scope hostname)
Description
After a user logs out of the webmail (?_task=logout, the link the UI itself offers: ./?_task=logout), the platform session cookie remains fully authenticated. A subsequent request to /roundcube/?_task=mail returns the user's live inbox without any re-authentication, and a request to the webmail root (/) immediately redirects back to /roundcube/?_task=mail — the proxy layer re-establishes the Roundcube session from its stored state. Logging out therefore does not end the session.
Steps to reproduce (standard Linux tools only, per program guidelines)
1. GET https://webmail.alwaysdata.com/ — obtain CSRF cookie and csrfmiddlewaretoken. 2. POST https://webmail.alwaysdata.com/ with csrfmiddlewaretoken, login=<mailbox>, password=<password> → 302 to /roundcube/?_task=mail; a platform session cookie is set. 3. GET /roundcube/?_task=mail&_mbox=INBOX → 200, <title>webmail :: Inbox</title> (pre-logout confirmation). 4. GET /roundcube/?_task=logout → 200 logout page (request is processed). 5. GET /roundcube/?_task=mail&_mbox=INBOX with Cache-Control: no-cache → 200, <title>webmail :: Inbox</title>, fully authenticated mailbox view. 6. GET https://webmail.alwaysdata.com/ → 302 back to /roundcube/?_task=mail — session re-established automatically.
Steps 5–6 reproduced on a fresh session, twice (initial observation plus a controlled retest), with cache-busting headers — this is not a cached-page artifact.
Impact
- A user who logs out on a shared or compromised machine believes their mail session has ended. Any party who captured the session cookie retains full mailbox access indefinitely — the standard mitigation ("log out") does not invalidate the credential. - The mailbox receives alwaysdata's own password-reset and account emails, so persistent mailbox access also means persistent reachability into the account-recovery flow of the platform.
Test account note
Testing was performed with a dedicated test account that I own and control; I can re-verify against a patched build on request. (Please keep this report free of the test credentials — happy to share them privately if useful for triage.)
|