justingit / dada-mail

Self-Hosted, Full Featured, Email Mailing List Manager. Announcement + Discussion Lists, Web-based Installer, Installs with minimal dependencies, sendmail/SMTP/Amazon SES supported
https://dadamailproject.com
GNU General Public License v2.0
169 stars 40 forks source link

Setting a custom administration login flavor and/or hiding the administration link is not useful security #1170

Open justingit opened 1 year ago

justingit commented 1 year ago

Anyone can access the login screen for the list control panel just by trying to visit any list control panel screen. For example, if you are not logged in, and you visit:

https://example.cgi/dada/mail.cgi?f=send_email

you'll be presented with a login screen.