You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Nov 4, 2024. It is now read-only.
I have identified a session fixation vulnerability, below is the steps to reproduce:
Step 1: Browse the application https://mail.rainloop.net/ in any browser and intercept the request over proxy.
Step 2: Now observe the session cookie "rlsession=bdecad79956032d7c64489ad2962a593"
Step 3: Now login into the application and again intercept the request of an authenticated page.
Step 4: Now again observe the cookie "rlsession=bdecad79956032d7c64489ad2962a593"
Step 5: The session cookie is same prior and post authentication which makes the application vulnerable to session fixation.