Description
The web application is based on Typo3 CMS. Typo3 Admin interface is publicly accessible.
Remediation
Restrict access to Typo3 Admin.
References
Related Vulnerabilities
Rails controller possible sensitive information disclosure
WordPress Plugin Video Embed & Thumbnail Generator Information Disclosure (1.1)
Joomla J!Dump extension enabled
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1507)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-28169)