This page is experimental and may change significantly in future releases.
ASP.NET Misconfiguration: Password in Configuration File
Properties
id: d3f:CWE-13
- name
- ASP.NET Misconfiguration: Password in Configuration File
- definition
- Storing a plaintext password in a configuration file allows anyone who can read the file access to the password-protected resource making them an easy target for attackers.
Neighbors
CWE-13 has no direct neighbors in this release.Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-13 has no related weaknesses in this release.