Web Cache Poisoing leads to ATO (Account takeover)

A Web cache poisoing on the login page leads to an Account Takeover using a simple header