id: syncthing-dashboard info: name: Syncthing Dashboard Exposure author: fabaff severity: medium description: Syncthing Dashboard is exposed. reference: - https://syncthing.net/ classification: cpe: cpe:2.3:a:syncthing:syncthing:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: syncthing product: syncthing shodan-query: http.html:'ng-app="syncthing"' tags: misconfig,syncthing,exposure http: - method: GET path: - '{{BaseURL}}' host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - 'The Syncthing Authors.' - 'Actions' condition: and - type: status status: - 200 # digest: 4a0a0047304502204da869e0540e660200659d2d578e9757250986a046fe7e5f9556a0a492c1d66d0221008a14e6282ee1d9bf306b43c877ed21e533f7913fdc7ff1f96901d32b68245f54:922c64590222798bb761d5b6d8e72950