Hi,
I find a security problem in Mantis 1.0.0-rc3
I desactivate the creation of account by email.
Only administrator can create user by the interface. The problem is that password appears in clear in the data base.
When the user changes his password the same problem appears.
Password must be encrypted in the database NO ?
Security Problem
Moderators: Developer, Contributor