Able to authenticate as administrator by navigating to https://█████/admin/

Disclosed: 2021-01-12 21:35:13 By nagli To deptofdefense
High
Vulnerability Details
**Summary:** The endpoint at https://███████/admin/ authenticates the user to the administrator user. ## Step-by-step Reproduction Instructions 1. Navigate to https://███/ and youll notice you will need to log in. 2. Navigating to https://██████████/admin/ will show you admin malformed page, with the ability to "log out" As for now as we can see by the picture no data is present at the administrator panel, sure this might change at the future exposing sensitive ifnormation ████████ ## Suggested Mitigation/Remediation Actions Issuing 403 response when trying to access the /admin endpoint. ##Best regards nagli ## Impact Admin authentication bypass
Actions
View on HackerOne
Report Stats
  • Report ID: 1035742
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report