gamonoid / icehrm

Manage your employees easily with a robust and efficient Human Resource Management System
http://icehrm.com
Other
579 stars 373 forks source link

Security - LDAP Authentication password #229

Open pantherale0 opened 3 years ago

pantherale0 commented 3 years ago

It seems that the LDAP authentication password is stored in plaintext? All users of IceHRM with Admin access can see the LDAP password. While the account is restricted anyway, isn't it best practice to hide this password on the web UI?