Jump to content

kennethhounsou

New Member
  • Posts

    1
  • Joined

  • Last visited

Everything posted by kennethhounsou

  1. Hi everyone, Am working for web hosting company and we use WHMCS We've recently conducted some security tests over our website and some points were noticed by the test team and reported to our attention to solve. We would like you recommendation about those to quickly sort them out. Lack of password length restrictions : a user can create a password over 1000 characters or more. How can we set a maximum limit of 365 characters for the password fields? firstname and lastname fields html injection : those fields at the user registration form can be filled with code as following "<a href=https://evil.com>clickhere</a>" How can we avoid this? Thanks for your recommendation, advice or any sort of guidance to go through this. PS: am not a developer. just in charge of running the whmcs website
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated