Adobe Connect User Community
Menu

#1 2011-02-09 05:54:19

**_kunoFM_**

Security issue in api.log

When logging to the api.log, the connect server replaces all passwords with "xxxxxxxxx".

But when using "user-update-pwd" the "password-verify" element (which has to be the same as the password for a successful change), is logged in clear text! So all user passwords appear in clear text in the api log! Thats bad :-(

[Connect Pro 7.5 latest SP]

Offline

Board footer