firezgi / team-spider-man

3 stars 2 forks source link

Team A | Vulnerability 3: Active Directories browsing is enabled for wordpress plugin locations #28

Open garanico opened 2 years ago

garanico commented 2 years ago

A number of directory listings are viewable with a GET request. Directory listings may reveal sensitive information

Report: https://docs.google.com/document/d/1HykJUftbZD7eepentH2hF8k8U3Jg10V4Xqk5QRxtDBA/edit#heading=h.n09rv4sqe1dv

Expected Outcome: Limit access to directories