Description
Acunetix determined that it was possible to access ImageResizer Diagnotics plugin without authentication.
Remediation
Restrict access to ImageResizer Diagnotics plugin
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7831)
Typo3 Admin publicly accessible
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.2)
TLS/SSL certificate key size too small
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2643)