observer.com URL should HTTPS

Disclosed: 2017-09-14 21:09:28 By bf7e43565d8cf54de3bc5a7 To legalrobot
Unknown
Vulnerability Details
#Summary This is just for the awareness to use HTTPS everywhere, even for outgoing links - where it's possible. Treat this report with some salt, not as in hashes. #Navigate to: https://www.legalrobot-uat.com/press/ Example page (In the lower part where you find the observer.com Link): observer redirect to HTTPS after click, but cookie is sent on the network before that. See my attached photo. {F212950} Related Issue : #1093 Thanks!
Actions
View on HackerOne
Report Stats
  • Report ID: 260299
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report