Loading HuntDB...

Wordpress directories/files visible to internet

Medium
U
Ubiquiti Inc.
Submitted None
Reported by tk0

Vulnerability Details

Technical details and impact analysis

Information Disclosure
#Issue During my testing I noticed that ubnt website `https://directory.corp.ubnt.com` seems to leak some data into internet. Wordpress directory `https://directory.corp.ubnt.com/wp-content/uploads/` is showing files which I suppose shouldn't be visible to internet. I noticed that these files include UBNT-employee email addresses (including personal?), pictures etc. #Reproduction Just open URL https://directory.corp.ubnt.com/wp-content/uploads/ and start browsing folders/files. Most "juicy" stuff can be seen in these folders: ██████████ BR, -Tomi

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure