Prestashop: Passwords in Welcome emails

Created on 12 Oct 2019  路  6Comments  路  Source: PrestaShop/PrestaShop

Description
The welcoming email sent when a user creates an account contains the username AND password in clear text. This means passwords are stored as clear text in the db, which is a serious security risk !

To Reproduce
Simply create an account

Email No change required

Most helpful comment

Since it's related to an old PrestaShop version, and the reporter is not the owner of the websites, I close this issue.

All 6 comments

What? :D Password are not stored in plain text... you can check it in database, table PREFIX_customer,

about an e-mail with registration confirmation... what version of PrestaShop you use?

I don't personally use PrestaShop, but I created an account on 2 websites that use it... and both sent me the same welcome email with my credentials in plain text !
I assumed it came from PrestaShop, but I don't know which version.

Ok, don't worry, passwords are not stored in plain text, also in newest versions of PrestaShop password is no longer sent after creating an account

By newer versions, he said, every versions that are over two or three years old 馃槄
https://github.com/PrestaShop/PrestaShop/pull/5889

Hi @Talw3g,

There is no password displayed in the PS1.7.6.1.
image
It is fixed with PS1.7 fixed with this PR: #5889
If you are using the PS1.6, it is fixed with this PR: https://github.com/PrestaShop/PrestaShop/pull/8564
Thanks to check & feedback.

Since it's related to an old PrestaShop version, and the reporter is not the owner of the websites, I close this issue.

Was this page helpful?
0 / 5 - 0 ratings