Have you ever seen plain-text credentials in the browser? Do you think, it’s an application vulnerability? The direct answer would be, No. That’s how the protocol works and it’s the intended behavior of the browser. Well, let’s dig into the question, “WHY?” It’s not an application vulnerability, since it’s only visible in the particular user’s browser and…