Autocompletion enabled on password fields

Overview

The user browser can save and remember the entered values for user input fields with autocomplete-enabled attributes. This might reveal sensitive information like passwords, especially on public and multi-user computers.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Rare

Incidence

How common is this issue?
1%0%
arrow down1%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
3 years6 months
arrow down82%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconOrganizational SecurityiconAuthenticationiconA05:2021 – Security Misconfigurationicon