General > General Discussion
Security Audit report queries
I have run a vulnerability scan and these notifications show up
User credentials are sent in clear text
HTML form without CSRF protection
how can we avoid these vulnalbilities???
Dmitriy Simushev:
I've answered at the GitHub because it can be treated as an issue that we should somehow fix. See: .
One more thing: you should use either github issue tracker or the forum, but definitely not both.
Hi rndagijimana,
What kind of vulnerability scan tool did you use to find the CSRF and cleartext ??
Thanks for your feedback ;)
[0] Message Index
Go to full version