yiiframework.com icon indicating copy to clipboard operation
yiiframework.com copied to clipboard

Session / remember me is not invalidated on password change

Open samdark opened this issue 5 years ago • 0 comments

Can be reproduced by logging in using multiple browsers. Then one of the browsers changes password. Another one stays logged in.

That allows potential attacker to exploit old devices and other outdated points of logging in.

Changing password should invalidate all user sessions including "remember me" cookies.

samdark avatar Feb 09 '20 19:02 samdark