Thats not extremly critical, because the passwords are hashed, but could be very bad.
A database is not something i would like to have available online to the public.
At least the user should be informed about this possibility to chose a proper, non-public available path.
Hello, the default location of the userdb is ../etc/pdns.users.sqlite3
If you have installed nsedit in a directory (reachable via https://server/nsedit), its possible to download the database trough https://server/etc/pdns.users.sqlite3.
Thats not extremly critical, because the passwords are hashed, but could be very bad. A database is not something i would like to have available online to the public.
At least the user should be informed about this possibility to chose a proper, non-public available path.
Best regards margau