Able to authenticate as administrator by navigating to https://█████/admin/
High
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
nagli
Vulnerability Details
Technical details and impact analysis
**Summary:**
The endpoint at https://███████/admin/ authenticates the user to the administrator user.
## Step-by-step Reproduction Instructions
1. Navigate to https://███/ and youll notice you will need to log in.
2. Navigating to https://██████████/admin/ will show you admin malformed page, with the ability to "log out"
As for now as we can see by the picture no data is present at the administrator panel, sure this might change at the future exposing sensitive ifnormation
████████
## Suggested Mitigation/Remediation Actions
Issuing 403 response when trying to access the /admin endpoint.
##Best regards
nagli
## Impact
Admin authentication bypass
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic