Skip to content
This repository has been archived by the owner on Jan 13, 2022. It is now read-only.

INSECURE: Lobby2 extension stores passwords in cleartext #141

Open
jompu opened this issue Dec 15, 2019 · 0 comments
Open

INSECURE: Lobby2 extension stores passwords in cleartext #141

jompu opened this issue Dec 15, 2019 · 0 comments

Comments

@jompu
Copy link

jompu commented Dec 15, 2019

It stores the passwords in cleartext and send a lost password in cleartext to users email.

You can verify this by just looking into DependentExtensions/Lobby2/PGSQL/Lobby2Message_PGSQL.cpp file and search for a password string.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant