ADManager Displays Changed Password in Plain Text (HTML)
When you change a password you must type that password into a visually protected pair of boxes (so that no secondary observer might Van Eck your password or similar). The password is transmitted to the server through a secure connection (SSL). Then the response from the server includes the changed password in plain text in the HTML of the response page:
Successfully updated the user properties |
Password ThisIsAFakePassword! |
Really? This is very un-secure. Can we eliminate that second line?
New to ADSelfService Plus?