The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
Or an intranet app originally and devs not expecting it to be exposed to the internet?
But i’d bet it wasn’t a mishap but an assumption gone wrong (or stale).
But it seems that this was third-party code, which I guess explains it.
You're probably right. Windows Server / IIS doesn't seem like them
Up until recently the team I was dropped into didn’t have any authentication for all their endpoints, I pointed this out and secured them all, except for one. This one endpoint was only used internally, but was still exposed.
During multiple security scans and a penetration test, this didn’t even come up.
I even had a hard time convincing our product manager this should be secured, and could be done in an hour or two, if I could get some time.