Loading HuntDB...

Unauthorised access to pagespeed global admin at https://webtools.paloalto.com/

P
Palo Alto Software
Submitted None
Reported by lordjerry0x01

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
## Summary: I came across this subdomain `https://webtools.paloalto.com/` which took my attention, after a bit enumeration I found an endpoint which allows anyone to access `PageSpeed Global Admin` without any type of authentication. ## Vulnerable URL: `https://webtools.paloalto.com/pagespeed-global-admin/` ## Impact You better know what can be done here.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic