Description
Acunetix determined that it is possible to access an installer of the web application without authentication. Depending on the installer, an attacker can takeover of the server.
Remediation
Restrict access to the installer
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1169)
Kentico Staging API publicly accessible
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1862)
WordPress Plugin Doneren met Mollie Information Disclosure (2.8.4)
WordPress Plugin SP Project & Document Manager Multiple Vulnerabilities (2.5.9.7)