full path disclosure at hosted.weblate.org/admin/accounts/profile/
Medium
W
Weblate
Submitted None
Actions:
Reported by
geekdad
Vulnerability Details
Technical details and impact analysis
Browsing this link https://hosted.weblate.org/admin/accounts/profile/ will ask for admin username and password as asked when browsing https://hosted.weblate.org/admin/accounts/ or https://hosted.weblate.org/admin/ hence disclosing the directory path of forbidden area.
screenshot : path.png
also it is found that there is no rate limiting enforced at https://hosted.weblate.org/admin/login/?next=/admin/ hence attacker can break into staffs account by brute forcing.
screenshot : login.png
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Path Traversal