Missing Password Field Masking |
Weakness ID: 549 (Weakness Variant) | Status: Draft |
Description Summary
The software fails to mask passwords during entry, increasing the potential for attackers to observe and capture passwords.
Recommendations include requiring all password fields in your web application be masked to prevent other users from seeing this information. |
Basic web application security measures include masking all passwords entered by a user when logging in to a web application. Normally, each character in a password entered by a user is instead represented with an asterisk. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 255 | Credentials Management | Development Concepts (primary)699 |
ChildOf | ![]() | 355 | User Interface Security Issues | Development Concepts699 |
ChildOf | ![]() | 522 | Insufficiently Protected Credentials | Research Concepts (primary)1000 |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
Anonymous Tool Vendor (under NDA) | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Other Notes, Taxonomy Mappings | ||||
2009-07-27 | CWE Content Team | MITRE | Internal | |
updated Relationships |