High severity Vulnerability

Sensitive Data Exposure

Passwords, keys or personal records travel unencrypted or sit in readable backups and logs.

Overview

The data is handled, but the protection around it is missing: HTTP instead of TLS, weak or no hashing for passwords, card numbers echoed in responses, API payloads full of fields the client never needs.\nBackups, error logs and Git history are common unintended stores of the same secrets.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Credentials sent over plain HTTP
  • MD5 or SHA-1 password hashes in a breach dump
  • Full object serialization returned by an API

Controls that stop it

  • Harden TLS and Security Headers

    Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used