Home
Description
Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.
References
www.sec4you-pentest.com/schwachstellen/
www.sec4you-pentest.com/...torisierter-zugriff-display_logo/