|
WorkforceROI Xpede Re-Authentication Plain Text Password Disclosure Vulnerability
An issue has been reported in Xpede which could allow a user to reveal the plain text password of users. When attempting re-authentication for a timed out session, Xpede uses Javascript to verify whether a user has enabled the 'Remember my password' option. Viewing the source of this Javascript will reveal the user's password in plain text. |
|
|
Privacy Statement |