Business logic Failure - Browser cache management and logout vulnerability.

Disclosed: 2014-05-18 01:52:50 By vhssunny1 To localize
Unknown
Vulnerability Details
Vulnerability class: Business logic Failure - Browser cache management and logout vulnerability. Vulnerability impact: Logging out from an application does not clear the browser cache of any sensitive information that have been stored. Steps to reproduce: 1. Login to portal. 2.browse few tabs 3. Click Logout 4. Click browser back button 5. you should able to see previous page and not only previous page but also viewed pages in the portal by clicking back back button Thanks Hari
Actions
View on HackerOne
Report Stats
  • Report ID: 7909
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report