PCI vulnerability for password field autocomplete=off
-
Hello,
We failed our recent, monthly PCI scan–apparently due to the Profile Builder Password field.
It appears that the Profile Builder Pro Password field allows auto completion (browsers caching/remembering the password).
In order for all Profile Builder Pro users to pass PCI scanning every time, this password field must have ‘autocomplete=off’ set.
While this is a user convenience I personally enjoy–the PCI standards won’t allow it.
An *easy* way to resolve this would be to enable an Autocomplete on/off checkbox in the admin settings.
Thank you for your help with this.
Chris
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘PCI vulnerability for password field autocomplete=off’ is closed to new replies.