From f55c4d28a0dc10349be320fca88cc346cb5c4f09 Mon Sep 17 00:00:00 2001 From: Anonymous Date: Thu, 1 Jan 1970 00:00:00 +0000 Subject: [PATCH] Added template for lidarr-settings-indexers --- lidarr-settings-indexers.yaml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 lidarr-settings-indexers.yaml diff --git a/lidarr-settings-indexers.yaml b/lidarr-settings-indexers.yaml new file mode 100644 index 00000000000..0f275f4c364 --- /dev/null +++ b/lidarr-settings-indexers.yaml @@ -0,0 +1,25 @@ +id: lidarr-settings-indexers + +info: + name: Lidarr Settings Indexers Exposure + author: ProjectDiscoveryAI + severity: medium + description: | + This template checks for exposed Lidarr indexer settings which can lead to sensitive information disclosure. + +http: + - raw: + - | + GET /lidarr/settings/indexers HTTP/1.1 + Host: {{Hostname}} + + matchers-condition: and + matchers: + - type: status + status: + - 200 + - type: word + words: + - "Lidarr" + - "Indexer" + - "Settings" \ No newline at end of file