Unauthorized Access to Internal Server Panel without Authentication

Disclosed: 2022-06-27 19:24:39 By ahmd_halabi To deptofdefense
Medium
Vulnerability Details
The server can be accessed without any authentication and it contains information that should not be kept public for anyone. I advice you to take look if this data are sensitive or not! ## References ███████ ## Impact There might be sensitive info that should not have to be leaked to public. ## System Host(s) ██████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Navigate to the target url: https://████/ See that you directly are inside the server without logging in. ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1548067
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report