![]() |
|
HackerOne Disclosed Reports - 2025-03-16 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-03-16 (/Thread-HackerOne-Disclosed-Reports-2025-03-16) |
HackerOne disclosed reports - 2025-03-16 - hashXploiter - 03-17-2025
Low
resolved Sensitive Information Disclosure via Back Button Post Logout on https://apps.nextcloud.com/account/Bug reported by Try_the_hack was disclosed at March 16, 2025, 2:50 pm | A cache control vulnerability was identified on the You are not allowed to view links. Register or Login to view. page. After logging out, sensitive information such as the user's first name, last name, and email address remained accessible by using the browser's back button. This occurred due to improper caching of authenticated pages, allowing unauthorized access to sensitive user information. |