|
Best Practical Solutions Request Tracker contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program fails to perform certain redirect actions upon login, which will disclose login credentials to a physically present attacker who uses a web browser's back button after a logout.
|