Update aem-login-status.yaml

patch-1
Dhiyaneshwaran 2022-03-12 14:26:52 +05:30 committed by GitHub
parent e910091f08
commit 8301e80261
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 0 deletions

View File

@ -4,6 +4,7 @@ info:
author: DhiyaneshDk
name: AEM Login Status
severity: info
description: LoginStatusServlet is exposed, it allows to bruteforce credentials.
reference:
- https://www.slideshare.net/0ang3el/hunting-for-security-bugs-in-aem-webapps-129262212
- https://github.com/thomashartm/burp-aem-scanner/blob/master/src/main/java/burp/actions/dispatcher/LoginStatusServletExposed.java