Nov 17, 2018 1:13:10 PM

SECURITY: bug in login form exposes password in plain text

The login form does not specify a method of POST and thus defaults to GET.

On login failure, the username and password are appended to the URL as GET parameters, exposing plaintext username and password to: browser history, webserver log, proxy server log, dns server log, etc.

Synametrics support engineer
Nov 28, 2018 7:57:55 AM

SECURITY: bug in login form exposes password in plain text


Thank you for letting us know about this. It will be fixed in the next update.


Social Media

Powered by 10MinutesWeb.com