Unauthorized Access to Internal Server Panel without Authentication
Medium
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
ahmd_halabi
Vulnerability Details
Technical details and impact analysis
The server can be accessed without any authentication and it contains information that should not be kept public for anyone.
I advice you to take look if this data are sensitive or not!
## References
███████
## Impact
There might be sensitive info that should not have to be leaked to public.
## System Host(s)
██████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Navigate to the target url: https://████/
See that you directly are inside the server without logging in.
## Suggested Mitigation/Remediation Actions
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic