
Axigen WebAdmin Improper Access Control Vulnerability
A flaw in the permission logic allows an administrator account with zero permissions to access the "Security & Filtering" page, specifically the SSL Certificates endpoint. While other restricted sections are correctly blocked, this endpoint remains unauthorizedly accessible.
Affected Versions: < 10.6.26
For more info, see the Axigen Knowledge Base.
Target URL:
https://{axigen-domain}:9443/?_h={admin-token}&page=sslcerts
Steps to Reproduce:
sslcerts page using the URL above.Result: The restricted user is granted access to view, download, upload, and delete certificate files.