Preview Tool

Cisco Bug: CSCsz33368 - password is sent in URL and is displayed to user in URL

Last Modified

Feb 05, 2017

Products (1)

  • Cisco Unified Contact Center Express

Known Affected Releases


Description (partial)

Symptom:password is sent in URL and is displayed to user in URL
in 2nd node, initial appadmin config, add to cluster page, user enters 1st node IP address, admin username and password and click next, the UCCX try to contact 1st uccx node and then add the 2nd node to the cluster. but if sue to some reason the 1st node is not reachable, the system pop up a message. then if user see the address bar of the browser he will see the password for admin user in the URL. this is happenning because the password is appended to the URL in plain text without any encryption. this should not be done . the page looks quite funny as the password is masked in the webpage and in the URL the password is seen in plain text :)
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.