<<< Date Index >>>     <<< Thread Index >>>

Powerschool 404 Admin Exposure



Powerschool 4.3.6 and possibly other versions expose the admin interface when 
requesting any file with .js

This allows one to see some directory and file names inside the admin folder.

POC:

http://[powerschoolip]/admin/.js

Product's website does not provide email contact?