Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.