CWE-549

Missing Password Field Masking

High

Description

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Potential Impact

How to Fix

Implementation

Recommendations include requiring all password fields in your web application be masked to prevent other users from seeing this information.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-549 vulnerabilities in your codebase.

Get Security Assessment