Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The API example shows `type=keygen&user=<user>&password=<pass>` in a URL query string without warning that credentials in URLs are commonly logged by browsers, proxies, reverse proxies, shells, and server access logs. Even in a read-only audit context, exposing admin credentials or API bootstrap credentials can enable unauthorized access and secondary compromise.
