Unauthorised access to pagespeed global admin at https://webtools.paloalto.com/
P
Palo Alto Software
Submitted None
Actions:
Reported by
lordjerry0x01
Vulnerability Details
Technical details and impact analysis
## Summary:
I came across this subdomain `https://webtools.paloalto.com/` which took my attention, after a bit enumeration I found an endpoint which allows anyone to access `PageSpeed Global Admin` without any type of authentication.
## Vulnerable URL:
`https://webtools.paloalto.com/pagespeed-global-admin/`
## Impact
You better know what can be done here.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic