Project

General

Profile

Actions

Defect #13197

closed

Don't send password in plain text via email after registration

Added by Martin Eberle about 11 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Cant reproduce
Affected version:

Description

When the registration process is set to manual account activation, the new user gets automatically an email with his (self set) username and password in plain text.

This is a dangerous security risk!

And it is not necessary. The user knows the password anyway, because it was set by himself.


Files

send_account_info.png (48.3 KB) send_account_info.png Jan from Planio www.plan.io, 2015-12-06 16:54

Related issues

Related to Redmine - Patch #21436: Prevent admins from sending themselves their own passwordClosedJean-Philippe Lang

Actions
Actions

Also available in: Atom PDF