- Joined
- Sep 11, 2012
- Messages
- 49
- Reaction score
- 8
Inspired by this thread in the Ideas forum: https://www.3cx.com/community/threads/security-risk.45381/
This feels like a very big deal to me and I think deserves more attention. Quoting my last post in that thread:
This feels like a very big deal to me and I think deserves more attention. Quoting my last post in that thread:
So, does 3cx not consider sending out <AuthPass></AuthPass> and <TunnelPass></TunnelPass> in plain text not a serious security concern?
The fact that we have not received any input from 3cx support makes it seem that way.
If any of those config files lands in the wrong hands, it could be very bad indeed.