Authentication bypass in ████████

Disclosed: 2022-12-02 13:00:21 By roland_hack To mtn_group
Critical
Vulnerability Details
## Summary: In a nutshell, an authentication bypass exploits weak authentication mechanisms to allow a hacker to access your systems and data.In a nutshell, an authentication bypass exploits weak authentication mechanisms to allow a hacker to access your systems and data ## Steps To Reproduce: 1.I was going to the site: █████ and on the home page I clicked on personal and the site redirected me to another site which is: ██████████ and on this site on which I was redirected I saw "link your NIN" and I went to this site and after listing I found an impressive thing which is the Tiny filemanager and to authenticate myself I bypass it with default credentials to access it. The default credentials are: Login Details: ████/████ | user/12345 and I had access to the panel and I had privileges like modify, upload, delete ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact The impact of authentication vulnerabilities can be very severe. Once an attacker has either bypassed authentication or has brute-forced their way into another user's account, they have access to all the data and functionality that the compromised account has.
Actions
View on HackerOne
Report Stats
  • Report ID: 1747146
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report