id: sftpgo-admin-setup info: name: SFTPGo Admin - Setup author: ritikchaddha severity: high description: | SFTPGo Admin Password setup page has been exposed. classification: cpe: cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: sftpgo_project product: sftpgo fofa-query: title="SFTPGo - Setup" tags: sftpgo,misconfig,setup http: - method: GET path: - "{{BaseURL}}/web/admin/setup" matchers-condition: and matchers: - type: word part: body words: - 'SFTPGo - Setup' - 'SFTPGo you need to create an admin user' condition: or - type: status status: - 200 # digest: 4a0a0047304502202367af7043922fc47812007e09bb071eb0c6dd4b4e64864853242c820a119e89022100f84abceaa411d208e74d76a4b32afe7724473ec419779f1bc0cb1b30bb662e7e:922c64590222798bb761d5b6d8e72950