漏洞描述
Exposed Grav admin user register page.
id: grav-register-admin
info:
name: Grav Register Admin User - Detect
author: DhiyaneshDk
severity: high
description: Exposed Grav admin user register page.
classification:
cpe: cpe:2.3:a:getgrav:grav_admin:*:*:*:*:grav:*:*:*
metadata:
verified: true
max-request: 1
vendor: getgrav
product: grav_admin
shodan-query: title:"Grav Register Admin User"
tags: grav,register,admin,misconfig,vuln
http:
- method: GET
path:
- "{{BaseURL}}/admin"
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'Grav Register Admin User | Grav'
- 'admin accounts'
condition: and
- type: status
status:
- 200
# digest: 490a0046304402201116d5489e0804274884983a49ef541b79dbed3e09328ef3ab6c94bcf6e26fc80220483fc0c82258eafbbc51da714d10296b44f84ab4c5b7a587245e43b5934e737f:922c64590222798bb761d5b6d8e72950