Default Admin Username and Password on ███

Disclosed: 2023-12-21 17:35:19 By maskedpersian To deptofdefense
Critical
Vulnerability Details
It is possible to access the application is using the default username and password Steps To Reproduce: 1-Go to https://███/geoportal/ and login with credentials: user and password: admin user and password: gptadmin Poc video attached ## Impact A Department of Defense website was misconfigured in a manner that may have allowed a malicious user to login with administrator for the default organization account credentials and delete posts , edit website ## System Host(s) ███ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce POC video ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 2262365
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report