Hello there, I've noted a security issue within the WHMCS system which relates to how product FTP passwords are viewed.
The issue is evident in the 'Client Profile' view, and when viewing the product, and the 'FTP Password' field (see attached screenshot).
The security issue relates to the fact that the password is viewable in plaintext, and is not in asterisk or 'input="password" format upon page load, and the form field does not have a 'reveal' button/function next to it to convert the password from asterisk to plain text, and back again. This function is now common, and a good example of this can be seen in Google's password manager.
This issue is more of an issue from a physical perspective (people standing over your shoulder and viewing the password, or a screenshot logger recording it on a compromised system).
Is there a fix for this that anybody is aware of, or any plans to release a fix? Thank you.