id: freshrss-unauth info: name: Freshrss Admin Dashboard - Exposed author: ritikchaddha severity: high description: | Freshrss Admin Dashboard has been exposed. metadata: max-request: 1 verified: true shodan-query: title:"Freshrss" tags: freshrss,misconfig,unauth,exposed http: - method: GET path: - "{{BaseURL}}/i/?a=logs" matchers-condition: and matchers: - type: word part: body words: - 'a=logout' - 'FreshRSS' - 'c=user&a=profile' condition: and - type: status status: - 200 # digest: 490a004630440220711bbfdcea48f25f55e1465d58bfd13ab15e3e265a3435e2e0c4eb6f05333ca502201aea2a64cb3967574dcca15eb39690a94c8a775529bc1de47ca4820df7f6f2ad:922c64590222798bb761d5b6d8e72950