Common Weakness Enumeration

    CWE Definition / CWE-523

    CWE-523: Unprotected Transport of Credentials

    Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-522: Insufficiently Protected Credentials

    CWE-319: Cleartext Transmission of Sensitive Information