NoSQL Injection: MongoDB ( 11687 )

Hello ebell
How should this vulnerability be fixed? Why is it considered a vulnerability when returning 302 and Cache-Control: private, no-cache, no-store, must-revalidate?

Tags: