Loading HuntDB...

Able to authenticate as administrator by navigating to https://█████/admin/

High
U
U.S. Dept Of Defense
Submitted None
Reported by nagli

Vulnerability Details

Technical details and impact analysis

Improper Authentication - Generic
**Summary:** The endpoint at https://███████/admin/ authenticates the user to the administrator user. ## Step-by-step Reproduction Instructions 1. Navigate to https://███/ and youll notice you will need to log in. 2. Navigating to https://██████████/admin/ will show you admin malformed page, with the ability to "log out" As for now as we can see by the picture no data is present at the administrator panel, sure this might change at the future exposing sensitive ifnormation ████████ ## Suggested Mitigation/Remediation Actions Issuing 403 response when trying to access the /admin endpoint. ##Best regards nagli ## Impact Admin authentication bypass

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authentication - Generic