Unauthorized Access To Admin Panel
Admin panels are publicly accessible and anyone can login to this host . Access to internal data makes changes without admin authentication.
Steps To Reproduce:
1.First create an account on main domain as user.
2.Now move to Admin Panel which is hosted on subdomain.
3.Now use same user credentials to login into Admin area.
4.BOOM . Account Login and Access to Admin Panel Successfully.
1.This subdomain should be accessible privately.
2.Only valid admin emails can be accessed.
3.No user email allowed.