Unauthorized Access To Admin Panel

  • Reported to Private
  • Reported by Haqtify
  • High (8.2)
  • $500
  • Published 3 years ago
  • No Likes



Summary :

Admin panels are publicly accessible and anyone can login to this host . Access to internal data makes changes without admin authentication.

Steps To Reproduce:

1.First create an account on main domain as user.


2.Now move to Admin Panel which is hosted on subdomain.


3.Now use same user credentials to login into Admin area.

4.BOOM . Account Login and Access to Admin Panel Successfully.



Remedy :

1.This subdomain should be accessible privately.
2.Only valid admin emails can be accessed.
3.No user email allowed.