Store Admin Page Accessible Without Authentication at http://www.grouplogic.com/ADMIN/store/index.cfm

Disclosed: 2022-06-07 10:20:01 By ub3rsick To acronis
Medium
Vulnerability Details
## Summary The store admin page is accessible without authentication at below URL: ``` http://www.grouplogic.com/ADMIN/store/index.cfm ``` The store admin page provides functionalities such as the following: - Add Edit Items - Search Products - Search Results - Search Orders - Orders Search Results - Add New Promo Code - Promo Code - Add New How Hear - How Hear ## Steps To Reproduce Navigate to below URL from a browser to access the store admin page. ``` http://www.grouplogic.com/ADMIN/store/index.cfm ``` ## Recommendations It is highly recommended to implement proper access controls on administrator functionalities. Only authenticated admin users are to be allowed to access admin pages. ## Impact Access to admin functionalities without authentication.
Actions
View on HackerOne
Report Stats
  • Report ID: 1164854
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report