Description
Acunetix determined that it was possible to access ImageResizer Diagnotics plugin without authentication.
Remediation
Restrict access to ImageResizer Diagnotics plugin
References
Related Vulnerabilities
Access-Control-Allow-Origin header with wildcard (*) value
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2484)