logo
Home/CWEs/CWE-13/

CWE-13 - ASP.NET Misconfiguration: Password in Configuration File

  • Abstraction:Variant
  • Structure:Simple
  • Status:Draft
  • Release Date:2006-07-19
  • Latest Modification Date:2023-06-29

Weakness Name

ASP.NET Misconfiguration: Password in Configuration File

Description

Storing a plaintext password in a configuration file allows anyone who can read the file access to the password-protected resource making them an easy target for attackers.

Common Consequences

Scope: Access Control

Impact: Gain Privileges or Assume Identity

Related Weaknesses

CWE-260Password in Configuration File