Loading HuntDB...

Unauthorized Access to Internal Server Panel without Authentication

Medium
U
U.S. Dept Of Defense
Submitted None
Reported by ahmd_halabi

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
The server can be accessed without any authentication and it contains information that should not be kept public for anyone. I advice you to take look if this data are sensitive or not! ## References ███████ ## Impact There might be sensitive info that should not have to be leaked to public. ## System Host(s) ██████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Navigate to the target url: https://████/ See that you directly are inside the server without logging in. ## Suggested Mitigation/Remediation Actions

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic