Auto complete enabled vulnerability

Autocomplete enabled

Severity: Medium

Vulnerability Description

Autocomplete when enabled provides ease of access to users and allows users not to type information repeatedly. However, when enabled for sensitive fields like usernames and passwords it leads to vulnerabilities like sensitive data exposure.

Impact

This ease of enabling auto-complete enabled allows an attacker to gather information related to the application and existing users and then leading to further attacks.

Attack simulation

 Observe by typing any text if any suggestion is come or not.

check at text box autocomplete field is marked as off or not from the developer options.

Recommendation

It is recommended that set auto complete of for a sensitive information like user name and password etc.

Affected URLs/parameters

Comments

Popular posts from this blog

Set password by default when transfering data through xender hot spot network.

Browser cache weakness

Email Phishing