Headline
Magento eCommerce 2.4.0 Information Disclosure
Magento eCommerce version 2.4.0 suffers from an information disclosure vulnerability.
====================================================================================================================================| # Title : Magento eCommerce v 2.4.0 sensitive information disclosure Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(32-bit) | | # Vendor : https://devdocs.magento.com/ | | # Dork : Index of /var/log/ |====================================================================================================================================poc : [+] Keeping records in an unprotected folder, The logs contain sensitive information such as folder path,etc...[+] Dorking İn Google Or Other Search Enggine .[+] http://127.0.0.1/dawnfrozenfoods.com/var/log/Greetings to :========================================================================================================================= |jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* | |=======================================================================================================================================