OPTIONS Method Enabled

Disclosed: 2014-04-21 07:03:33 By simon90 To localize
Unknown
Vulnerability Details
HTTP OPTIONS method is enabled on the web server of Localize. The OPTIONS method provides a list of the methods that are supported by the web server, it represents a request for information about the communication options available on the request/response chain identified by the Request-URI. This vulnerability affects the Web Server of InvisionApp! Attack details: Methods allowed: GET,HEAD,POST,OPTIONS The OPTIONS method may expose sensitive information that may help an malicious user to prepare more advanced attacks. Fix:It's recommended to disable OPTIONS Method on the web server.
Actions
View on HackerOne
Report Stats
  • Report ID: 8184
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report