hide-login has url vulnerability/hack
-
I am using this plugin which is pretty nifty. I did notice however, that there is a slight vulnerability in the URL that can allow someone to bypass it if they get a part of the URL correct.
For example.
https://www.example.com/login is what I have it set to.
if I were to put this:
‘www.example.com/loginnowbecauseisayso’ I would be able to get in. This URL regex schema is not 100%
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘hide-login has url vulnerability/hack’ is closed to new replies.