Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/usd-2020-0053/ | third party advisory exploit |