Access to ██████████████ due to weak credentials

Disclosed: 2020-01-08 20:37:28 By kingragnar To 8x8
Medium
Vulnerability Details
Hi Team **Description:** During the analysis, It was found that the `█████████████████████` ask's for credentials from the users to access the ██████, But the weak credentials set `█████:██████` allows anyone to login. ## Steps To Reproduce: 1. Open █████████████████████████ 1. Enter `█████████` ███████ username and password field. 1. You now have access to the analytical data. ## POC ███ ## Remediation Use strong set of password instead of common████generic ones like `████:██████` ## Impact An attacker can bypass the authentication check and access the internal analytical data. PS: apart from the analytical data, I wasn't able to find much.
Actions
View on HackerOne
Report Stats
  • Report ID: 692116
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report