|
Task Description
Hello Alwaysdata Security Team,
I understand that `boidcms.alwaysdata.net` may be outside the scope of your current bug bounty program. Nevertheless, I wanted to bring this to your attention because of the potential security impact.
I discovered that the following administration interface is accessible using default credentials:
https://boidcms.alwaysdata.net/admin
The default credentials allow authentication to the CMS administrative panel. (Username: admin, Password: password)
### Potential impact
If these credentials are intentionally deployed as part of a default CMS installation, anyone who knows or discovers them could potentially obtain administrative access to the application.
Depending on the permissions available through the panel, this could potentially allow an attacker to:
* Modify website/application content * Change application configuration * Create or modify administrative accounts * Access information available to the CMS administrator * Potentially upload or modify application files, depending on the CMS configuration
I did not make any changes to the application or attempt to perform destructive actions. My testing was limited to verifying that the default credentials provide administrative access.
I understand that this host may be outside the current scope of the bug bounty program. Nevertheless, I am reporting this issue in good faith because the default credentials provide administrative access and may present a meaningful security risk.
If the issue is determined to be eligible under the program or otherwise attributable to Alwaysdata, I would appreciate consideration for a bounty based on its security impact.
I can provide additional evidence and reproduction details if useful.
Thank you for taking a look.
Best regards, Saad Security Researcher
|