Web Host Directory Forums

View original thread:  ModernBill security flaw


Pages: 1 
gardanni
I observed a significant security flaw in Modernbill. Client account passwords are available to admin users in plain-text. This means that a disgruntled employee can collect passwords from all accounts and engage in a wide range of fraud activities. This also means that, considering that many people use the same passwords repeatedly, people using modern-bill based systems are vulnerable to being victims of fraud in other ecommerce accounts as well.
navyhost
darn... have you emailed them? They can probably have this fixed asap.
Return to Thread List