Description
Devise is a flexible authentication solution for Rails with Warden.
This page is using a weak Devise password. Acunetix was able to guess the credentials required to access this page. A weak password is short, common, a system default, or something that could be rapidly guessed by executing a brute force attack using a subset of all possible passwords, such as words in the dictionary, proper names, words based on the user name or common variations on these themes.
Remediation
Enforce a strong password policy. Don't permit weak passwords or passwords based on dictionary words.
References
Related Vulnerabilities
WordPress Plugin CodeArt-Google MP3 Player Arbitrary File Disclosure (1.0.11)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Information Disclosure (3.2.10)
SAP weak/predictable user credentials
WordPress 6.1.x Multiple Vulnerabilities (6.1 - 6.1.3)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19968)