DerScanner
  • Platform
    SAST
    Find vulnerabilities and quality issues in source code
    DAST
    Test running applications and APIs from the outside
    SCA
    Manage open source risk across your software supply chain
    MAST
    Security testing for iOS and Android applications
    On-premise Agentic AI
    AI agents that triage findings and suggest fixes automatically
    Delphi Security
    SAST, SCA, SBOM & Code Quality built for Delphi and Object Pascal
    Compliance & Standards support
    PCI DSS, OWASP, CWE, GDPR, CRA, and many more
    Vulnerability ScannerHighly Accurate
    Deep source code analysis with high accuracy and low false positive rate
    Code Quality Analysis
    Catch bugs, code flaws, and maintainability issues
    SAST/DAST Correlation
    Cross-validate findings to cut false positives
    Rare & Legacy Language Support
    Delphi, COBOL, ABAP, Perl, PL/SQL, 1C, and others
    Resources
    Blog
    Vulnerability Database
    Documentation
    Videos
    Comparisons
    Community Contribution
    Book a demo
    Talk to the team
    Start a PoC
  • By Industry
    By Use Case
    Healthcare
    Legacy stack and patient data flow tested for HIPAA compliance
    Automotive
    Embedded code tested against ISO/SAE 21434 and UN R155
    Financial Services
    Core banking, payments and vendor software under DORA and PCI DSS
    Telecom
    Portals, billing, OSS and vendor software under NIS2
    Managed Security Service Providers
    White-label scanning for MSSP, audit and advisory teams
    On-premise / Air-gapped environments
    Full scanning power with zero outbound connectivity required
    Resources
    Blog
    Vulnerability Database
    Documentation
    Videos
    Comparisons
    Community Contribution
    Book a demo
    Talk to the team
    Start a PoC
  • Pricing
  • Partners
  • About Us
Home / Vulnerability Database / Dart : Unhidden password field
Dart

Dart : Unhidden password field

Classification

OWASP Top 10 2013
A2-Broken Authentication and Session ManagementA6-Sensitive Data Exposure
OWASP Top 10 2017
A2-Broken AuthenticationA3-Sensitive Data Exposure
OWASP Top 10 2021
A2-Cryptographic FailuresA4-Insecure DesignA7-Identification and Authentication Failures
OWASP ASVS
AuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthenticationAuthentication
PCI DSS 4.0
6.2.48.3.2
HIPAA
§164.312 (a)(1)§164.312 (a)(2)(iv)
CWE
CWE-256CWE-260CWE-261CWE-522CWE-1028CWE-1032
CWE/SANS Top 25 2021
CWE-522

Overview

The application may have an unhidden password field. This can lead to the application data being compromised.

References

  1. OWASP Top 10 2017-A2-Broken Authentication
  2. OWASP Top 10 2017-A3-Sensitive Data Exposure
  3. OWASP Top 10 2013-A5-Security Misconfiguration
  4. OWASP Top 10 2013-A6-Sensitive Data Exposure
  5. CWE CATEGORY: OWASP Top Ten 2017 Category A2 - Broken Authentication
  6. CWE CATEGORY: OWASP Top Ten 2017 Category A6 - Security Misconfiguration
  7. CWE-256: Unprotected Storage of Credentials
MEDIUM

DerScanner Severity Score

Do you want to fix Dart : Unhidden password field in your application?

See also

Dart

Dart : Cookie: broad domain

Dart

Dart : Cookie: broad path

Dart

Dart : Undocumented feature: special account

Platform

  • Static Application Security Testing
  • Dynamic Application Security Testing
  • Software Composition Analysis
  • Mobile Application Security Testing
  • Delphi Security
  • Compliance & Standards

Features

  • Highly Accurate Vulnerability Scanner
  • Code Quality Analysis
  • SAST/DAST Correlation (IAST)
  • Rare & Legacy Language Support
  • Web Application Security Testing
  • SBOM Generation
  • Supply Chain Security
  • Android Security Testing
  • iOS Security Testing

Solutions By Industry

  • Healthcare
  • Automotive
  • Financial Services
  • Telecom
  • MSSP & Consulting

Use Cases

  • On-premise / Air-gapped

Resources

  • Blog
  • Vulnerability Database
  • Documentation
  • Videos
  • Comparisons
  • Pricing

Company

  • About Us
  • Partners
  • Community Contribution
DerScanner

DerScanner is a full-cycle application security testing platform that unifies SAST, DAST, SCA, and MAST to secure code, dependencies, and running applications across the SDLC. AI-powered triage cuts false positives by up to 90%, and AI-powered code fix generates context-aware fixes, turning findings into actionable results. Findings map to major security standards and generate audit-ready reports – on-premise, in the cloud, or air-gapped.

Privacy Policy|Terms & Conditions|Cookie Policy|
Copyright © 2026 DerSecur