View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
16666 | Bug reports | Security | public | 2020-09-14 09:49 | 2021-07-12 14:08 |
Reporter | phitho | Assigned To | c_schmitz | ||
Priority | none | Severity | minor | ||
Status | closed | Resolution | duplicate | ||
Product Version | 3.23.3 | ||||
Fixed in Version | 5.x | ||||
Summary | 16666: Registration (continue later): Bounced E-Mail with visible password | ||||
Description | One of my participants wanted to continue later and signed up with his e-mail address. There was a 554 error and the e-mail bounced to the administrator - with visible log-in credientials (e-mail and password). | ||||
Tags | security | ||||
Bug heat | 254 | ||||
Complete LimeSurvey version number (& build) | Version 3.23.3+200909 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | I'm not the admin | ||||
Server OS (if known) | |||||
Webserver software & version (if known) | |||||
PHP Version | I'm not the admin | ||||
Seconding. In fact, the BIG problem here is that the user is prompted for a password at all -- the user may be fooled into using a browser-prompted password for the user's logons on the same domain, which is completely INSECURE. So EITHER, the user should be sent a randomly generated password (or better yet, link) OR the password is not ever sent out plain text, but salted and hashed before POSTing. Alternatively, you can try to creatively figure out how to reverse-engineer Chrome's usability engineers with javascript+HTML to disable auto-fill of the password fields: https://stackoverflow.com/questions/15738259/disabling-chrome-autofill |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2020-09-14 09:49 | phitho | New Issue | |
2020-11-05 13:49 | uibklime1 | Issue Monitored: uibklime1 | |
2020-11-05 14:07 | uibklime1 | Note Added: 60560 | |
2020-11-05 14:09 | uibklime1 | Tag Attached: security | |
2021-01-13 08:56 | DenisChenu | Category | Encryption => Security |
2021-01-13 08:59 | DenisChenu | Relationship added | duplicate of 11848 |
2021-07-12 14:08 | c_schmitz | Assigned To | => c_schmitz |
2021-07-12 14:08 | c_schmitz | Status | new => closed |
2021-07-12 14:08 | c_schmitz | Resolution | open => duplicate |
2021-07-12 14:08 | c_schmitz | Fixed in Version | => 5.x |