full path disclosure at hosted.weblate.org/admin/accounts/profile/

Disclosed: 2017-05-17 14:07:42 By geekdad To weblate
Medium
Vulnerability Details
Browsing this link https://hosted.weblate.org/admin/accounts/profile/ will ask for admin username and password as asked when browsing https://hosted.weblate.org/admin/accounts/ or https://hosted.weblate.org/admin/ hence disclosing the directory path of forbidden area. screenshot : path.png also it is found that there is no rate limiting enforced at https://hosted.weblate.org/admin/login/?next=/admin/ hence attacker can break into staffs account by brute forcing. screenshot : login.png
Actions
View on HackerOne
Report Stats
  • Report ID: 225495
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report