I Observed a Session Management Behavior After Password Reset — What I Learned About CWE-613
Introduction
While learning Web Application Security and Bug Bounty, I wanted to understand how applications handle existing authenticated sessions when a user changes or resets their password.
I test
nikhilsamineni.hashnode.dev7 min read