Wordpress directories/files visible to internet
Medium
U
Ubiquiti Inc.
Submitted None
Actions:
Reported by
tk0
Vulnerability Details
Technical details and impact analysis
#Issue
During my testing I noticed that ubnt website `https://directory.corp.ubnt.com` seems to leak some data into internet. Wordpress directory `https://directory.corp.ubnt.com/wp-content/uploads/` is showing files which I suppose shouldn't be visible to internet.
I noticed that these files include UBNT-employee email addresses (including personal?), pictures etc.
#Reproduction
Just open URL https://directory.corp.ubnt.com/wp-content/uploads/ and start browsing folders/files.
Most "juicy" stuff can be seen in these folders: ██████████
BR,
-Tomi
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure