View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 17384 | Bug reports | Security | public | 2021-06-22 17:03 | 2021-07-08 11:13 |
| Reporter | bcanova | Assigned To | |||
| Priority | none | Severity | minor | ||
| Status | closed | Resolution | open | ||
| Product Version | 3.25.20 | ||||
| Summary | 17384: Web application does not restrict browser storage of passwords | ||||
| Description | Inspection of application communications reveals that the AUTOCOMPLETE attribute is not disabled in HTML FORM/INPUT element containing password type input on the administrator login page. Passwords may be stored in browsers and retrieved after a session terminates. Leaving authentication credentials stored at the client level allows potential access to session information that can be used by subsequent users of a shared workstation and could also be exported and used on other workstation providing immediate unauthorized access to the application. | ||||
| Additional Information | Configure the application to require the user to manually enter their credentials prior to each session. Disable the AUTOCOMPLETE attribute in any HTML forms or individual input elements containing passwords. For example, AUTOCOMPLETE="OFF". | ||||
| Tags | No tags attached. | ||||
| Attached Files | |||||
| Bug heat | 256 | ||||
| Complete LimeSurvey version number (& build) | 3.27.4 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | Chrome | ||||
| Database type & version | MyQL 5.5.9 | ||||
| Server OS (if known) | CentOS 7 | ||||
| Webserver software & version (if known) | |||||
| PHP Version | 7.2.5 | ||||
|
THIS IS NOT AN ISSUE ! Disable save password is a SECURITY issue ! |
|
|
What are you saying, Denis? It is or isn't? |
|
|
We have a lot of issue reported about "autocomplete=off" But : this is NOT a security issue : read the link
Maybe we can disable it in token form : because it's not really a password. And in config (smtp and imap password ) : but it's already done if i don't make error. Automatic system for tracking security giving bad advice … this is really a good tool ? |
|
|
I agree with @DenisChenu this is not a security issue. You may create a feature request if this is a priority for you and we will take a look at it. I will close this report. |
|
|
I open the 2 other «issue» about token and mail password. Maybe :
|
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2021-06-22 17:03 | bcanova | New Issue | |
| 2021-06-22 17:03 | bcanova | File Added: image.png | |
| 2021-06-22 17:03 | bcanova | File Added: image-2.png | |
| 2021-06-22 17:03 | bcanova | File Added: image-3.png | |
| 2021-06-22 17:07 | DenisChenu | Note Added: 64989 | |
| 2021-06-24 09:25 | ollehar | Note Added: 65037 | |
| 2021-06-24 09:32 | DenisChenu | Note Added: 65038 | |
| 2021-07-08 10:50 | galads | Note Added: 65255 | |
| 2021-07-08 10:50 | galads | Status | new => closed |
| 2021-07-08 10:59 | galads | Note Added: 65256 | |
| 2021-07-08 11:13 | DenisChenu | Note Added: 65257 |