rgonek / Ilaro.Admin

Generic admin panel for ASP.NET MVC.
http://admin.ilaro.net/
MIT License
131 stars 36 forks source link

Authentication Flaw #25

Closed mfaheemakhtar closed 8 years ago

mfaheemakhtar commented 8 years ago

The admin panel can be accessed without any login credentials. [Sign out button will be invisible]

Proof: Just visit: http://admin.ilaro.net/Admin

rgonek commented 8 years ago

Thanks for catching that.