Summary

Netsparker detected that WebDAV is enabled on this server and this directory has write permissions enabled. Netsparker was able to create a test file within this directory using the PUT method. After the test, Netsparker tried to delete the file.

Impact
Malicious users may create or modify files in this directory without providing any type of authentication and they might;
  • Gain full access to the application server.
Remediation
Restrict access for method PUT or if it's not being used, consider disabling it.
Classifications
PCI v3.1-6.5.8, PCI v3.2-6.5.8, WASC-17 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C