Quantcast
Channel: Developer to developer
Viewing all articles
Browse latest Browse all 9076

Login posts user name and password as clear text

$
0
0

When using standard Episerver CMS login, the password and user name is posted as clear text.

To reproduce...

  1. Open Chrome and whip out Developer Tools and select the Network tab. Check Preserve log.
  2. Open your CMS site at /util/login.aspx and log on with your user credentials.
  3. Select the first login.aspx in the list of network traffic in Developer Tools and click the Headers tab.
  4. Locate form data at the bottom, to view your user name and password in clear text.

Any thoughts on this? Is it supposed to be like that?


Viewing all articles
Browse latest Browse all 9076

Trending Articles