Auto complete enabled vulnerability
Severity:
Medium
Vulnerability Description
Autocomplete
when enabled provides ease of access to users and allows users not to type
information repeatedly. However, when enabled for sensitive fields like usernames
and passwords it leads to vulnerabilities like sensitive data exposure.
Impact
This ease of enabling
auto-complete enabled allows an attacker to gather information related to the
application and existing users and then leading to further attacks.
Attack simulation
check at text box autocomplete field is marked as off or not from the developer options.
Recommendation
It is recommended that set auto complete of for
a sensitive information like user name and password etc.
Affected URLs/parameters
Comments
Post a Comment