Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WorkforceROI Xpede Re-Authentication Plain Text Password Disclosure Vulnerability

An issue has been reported in Xpede which could allow a user to reveal the plain text password of users.

When attempting re-authentication for a timed out session, Xpede uses Javascript to verify whether a user has enabled the 'Remember my password' option. Viewing the source of this Javascript will reveal the user's password in plain text.







 

Privacy Statement
Copyright 2008, SecurityFocus