When logging in to the ControlID system, it was possible to notice that the application sends the access credentials in clear text through cookies.

Untitled

Untitled