Description
Acunetix determined that it is possible to access an installer of the web application without authentication. Depending on the installer, an attacker can takeover of the server.
Remediation
Restrict access to the installer
References
Related Vulnerabilities
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.30)
Jetty Information Disclosure (CVE-2021-34429)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.22)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16738)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7890)