image.png

Recon

simple network map scan:

nmap -sS -sV -T5 192.168.1.138 -p-

image.png

Notes:

Starting with a simple look on the browser:

image.png

Followed with Fuzzing on the target:

image.png

The fuzzing reveals a/backend path that redirect us to /backend/backend/auth/signin

image.png

→ Exposed Admin panel for OctoberCMC