View Issue Details

This bug affects 1 person(s).
 4
IDProjectCategoryView StatusLast Update
08930Bug reportsInstallationpublic2014-04-22 21:28
ReporterDenisChenu Assigned ToDenisChenu  
PrioritynormalSeverityminor 
Status closedResolutionfixed 
Product Version2.05+ 
Fixed in Version2.06+ 
Summary08930: Remove the password in last installation step
Description

At the last installation step we have:
Nom d'utilisateur: UserNameChoosen
Mot de passe : PassWorChoosen

It's a security issue, and user choose his password write it 2 times).

Additional Information

Better to have:
Nom d'utilisateur: UserNameChoosen
Mot de passe : The password you choose before (fixed string)

TagsNo tags attached.
Attached Files
Bug heat4
Complete LimeSurvey version number (& build)140402
I will donate to the project if issue is resolvedNo
Browsernot relevant (FF28)
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)not relevant
PHP Versionnot relevant

Users monitoring this issue

There are no users monitoring this issue.

Activities

c_schmitz

c_schmitz

2014-04-08 09:52

administrator   ~29689

I am sorry but I fail to see the security issue. Can you explain a bit more, please?

DenisChenu

DenisChenu

2014-04-08 10:08

developer   ~29691

Showing a password on screen allow atacker to see password (social risk), and i think we really don't need to show the password.

It's really a low security risk, it's why i don't fix it and put a bug report (really quick to fix).

c_schmitz

c_schmitz

2014-04-22 21:28

administrator   ~29861

2.05+ Build 140422 released.

Related Changesets

LimeSurvey: 2.06 99c2d735

2014-04-11 11:02:33

DenisChenu

Details Diff
Fixed issue : 08930: No need to show admin password at last step if it was updated
Dev: Fixed issue when unable to create the DB (broken HTML page)
Affected Issues
08930
mod - application/controllers/InstallerController.php Diff File

Issue History

Date Modified Username Field Change
2014-04-02 10:24 DenisChenu New Issue
2014-04-08 09:51 c_schmitz Assigned To => c_schmitz
2014-04-08 09:51 c_schmitz Status new => assigned
2014-04-08 09:52 c_schmitz Note Added: 29689
2014-04-08 09:52 c_schmitz Status assigned => feedback
2014-04-08 10:08 DenisChenu Note Added: 29691
2014-04-08 10:08 DenisChenu Status feedback => assigned
2014-04-08 10:15 DenisChenu File Added: Capture du 2014-04-08 10:14:44.png
2014-04-08 10:21 c_schmitz Assigned To c_schmitz => DenisChenu
2014-04-15 14:50 DenisChenu Changeset attached => LimeSurvey 2.06 99c2d735
2014-04-15 14:50 DenisChenu Status assigned => resolved
2014-04-15 14:50 DenisChenu Fixed in Version => 2.06+
2014-04-15 14:50 DenisChenu Resolution open => fixed
2014-04-22 21:28 c_schmitz Note Added: 29861
2014-04-22 21:28 c_schmitz Status resolved => closed