Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by Newname001 - 05.09.2026
Last edited by cbay - 06.09.2026

FS#473 - Default Credentials Allow Administrative Access on boidcms.alwaysdata.net

Hello Alwaysdata Security Team,

I understand that `boidcms.alwaysdata.net` may be outside the scope of your current bug bounty program. Nevertheless, I wanted to bring this to your attention because of the potential security impact.

I discovered that the following administration interface is accessible using default credentials:

https://boidcms.alwaysdata.net/admin

The default credentials allow authentication to the CMS administrative panel. (Username: admin, Password: password)

### Potential impact

If these credentials are intentionally deployed as part of a default CMS installation, anyone who knows or discovers them could potentially obtain administrative access to the application.

Depending on the permissions available through the panel, this could potentially allow an attacker to:

* Modify website/application content
* Change application configuration
* Create or modify administrative accounts
* Access information available to the CMS administrator
* Potentially upload or modify application files, depending on the CMS configuration

I did not make any changes to the application or attempt to perform destructive actions. My testing was limited to verifying that the default credentials provide administrative access.

I understand that this host may be outside the current scope of the bug bounty program. Nevertheless, I am reporting this issue in good faith because the default credentials provide administrative access and may present a meaningful security risk.

If the issue is determined to be eligible under the program or otherwise attributable to Alwaysdata, I would appreciate consideration for a bounty based on its security impact.

I can provide additional evidence and reproduction details if useful.

Thank you for taking a look.

Best regards,
Saad
Security Researcher

Closed by  cbay
06.09.2026 18:05
Reason for closing:  Invalid
Admin
cbay commented on 06.09.2026 18:05

Hello,

It's out of our scope since that site belongs to a client.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing