awardle Posted April 27, 2010 Share Posted April 27, 2010 Hi, This weekend my smartermail account was hacked by what seems to be some new exploit, it seems it was a targetted attack as the hacker gained access to my webmail then went to the WHMCS Admin area and requested a password reset. The hacker then logged in WHMCS admin and looked at some of my customers product information pages, luckily enough I was online at the time and was alerted of the password change so blocked access very quickly however it's a little concerning that WHMCS shows hashed passwords in the admin area for users products etc but when you view the HTML Source you can see the users full password. Is there a way to stop WHMCS outputting passwords to the webpages? Thanks Aaron 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.