Nov 8, 2019 08:34:47 AM by Muhammad Bilal I
Nov 10, 2019 04:30:54 PM by Aleksandar D
Hi Muhammad,
Thanks for reporting this to us! I already sent your report with our mobile team.
Thank you.
Nov 10, 2019 05:17:38 PM by Jennifer M
Muhammad Bilal I wrote:
I am using android app for freelancers and today while logging in, I entered wrong password by mistake.. Upon getting error, I clicked on Forgot password, even though the password was saved into my Google account password manager, it did not populated, however while proceedings for forget password, I was required to enter Captcha and ironically, my password was populated in plain text there, I used that one to remember and logged in. Here I think some sort of bug in app as the password must be hidden at any cost, 2ndly if Google password manager has stored then it should be allowed for used however it should never consider the captcha field as password and populate the password as plain text. Hope to see the issue resolved soon. Looking forward
brah they have a bug bounty and this is a good find.
User | Count |
---|---|
466 | |
402 | |
400 | |
379 | |
311 |