Wordpress directories/files visible to internet
Medium
Vulnerability Details
#Issue
During my testing I noticed that ubnt website `https://directory.corp.ubnt.com` seems to leak some data into internet. Wordpress directory `https://directory.corp.ubnt.com/wp-content/uploads/` is showing files which I suppose shouldn't be visible to internet.
I noticed that these files include UBNT-employee email addresses (including personal?), pictures etc.
#Reproduction
Just open URL https://directory.corp.ubnt.com/wp-content/uploads/ and start browsing folders/files.
Most "juicy" stuff can be seen in these folders: ██████████
BR,
-Tomi
Actions
View on HackerOneReport Stats
- Report ID: 201984
- State: Closed
- Substate: resolved
- Upvotes: 18