An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.
rapid7·CWE-201·Published 2025-05-29