Thanks to visit codestin.com
Credit goes to github.com

Skip to content

User's password can be seen in clear text #37

@californinson

Description

@californinson

If a user has already accessed a device and has the "remember credentials" enabled, someone else is able to see their clear text password in the page code by simply selecting one of the already accessed devices from the "host" list on the login page.

Once the username and password are automatically filled, the password is hidden by the browser but the string can be inspected and it can be seen in clear text in the page code.
Screenshot 2024-09-18 at 12 55 49
Screenshot 2024-09-18 at 13 27 59

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions