Information Exposure Through Directory Listing vulnerability
Medium
Vulnerability Details
A directory listing provides an attacker with the complete index of all the resources located inside of the directory as well as download or access its contents.
While the researcher did not dig deeper on to the available files, it might be possible that these websites host sensitive information like private videos which can publicly be downloaded or accessed by any user.
Steps To Reproduce:
Browse to the URLs below to see the vulnerability.
visit
1.https://apps.nextcloud.com/static/admin/
2.https://apps.nextcloud.com/static/admin/js/
## Impact
attacker can able to see the source code of users admin pages..
critical information of admin ..
Actions
View on HackerOneReport Stats
- Report ID: 1476709
- State: Closed
- Substate: informative
- Upvotes: 2