hi all,
recently in our pen test our auditor found out
"The application did not invalidate logged off’s session ID/Token. Tester was able to browse restricted page after restored cookies backed up from an authenticated session."
is there any solution on this?