diff --git a/exposures/configs/coremail-config-disclosure.yaml b/exposures/configs/coremail-config-disclosure.yaml new file mode 100644 index 0000000000..394ce246de --- /dev/null +++ b/exposures/configs/coremail-config-disclosure.yaml @@ -0,0 +1,21 @@ +id: coremail-config-disclosure +info: + name: Coremail Config Disclosure + author: princechaddha + severity: high + reference: https://www.secpulse.com/archives/107611.html + tags: config,exposure + +requests: + - method: GET + path: + - '{{BaseURL}}/mailsms/s?func=ADMIN:appState&dumpConfig=/' + matchers-condition: and + matchers: + - type: word + words: + - "" + - 'containerDefinitions' + - type: status + status: + - 302