Information Exposure Through Directory Listing vulnerability

Disclosed: 2022-02-11 08:05:57 By b82e8b928c2b3d60a82d6ec To nextcloud
Medium
Vulnerability Details
A directory listing provides an attacker with the complete index of all the resources located inside of the directory as well as download or access its contents. While the researcher did not dig deeper on to the available files, it might be possible that these websites host sensitive information like private videos which can publicly be downloaded or accessed by any user. Steps To Reproduce: Browse to the URLs below to see the vulnerability. visit 1.https://apps.nextcloud.com/static/admin/ 2.https://apps.nextcloud.com/static/admin/js/ ## Impact attacker can able to see the source code of users admin pages.. critical information of admin ..
Actions
View on HackerOne
Report Stats
  • Report ID: 1476709
  • State: Closed
  • Substate: informative
  • Upvotes: 2
Share this report