Vulnerabilities/

html inputs of type password recorded in plaintext when converted to text inputs

Severity:
Medium

Description

Highlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript “Show Password” button. This differs from the expected behavior which always obfuscates type="password" inputs.

Recommendation

Update the highlight.run package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
highlight.run
Anything's wrong? Let us know Last updated on November 08, 2023

This issue is available in SmartScanner Professional

See Pricing