S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 10, 2026

CVE-2021-46371 Scanner

CVE-2021-46371 Scanner - Information Disclosure vulnerability in AntD Admin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-46371
7.5
CVSS

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

AntD Admin is a popular front-end development solution used in creating web interfaces. It is often used by developers to streamline the process of building user-friendly web applications. The tool is pervasive across industries that require efficient administrative panels or dashboards for data management and visualization. Its components facilitate manipulation of data and interaction with backend services. AntD Admin delivers flexibility and customization, offering a wide array of UI components to enhance the user experience. It is a valuable asset for developers seeking to implement a robust administrative interface with a modern look and feel.

The vulnerability detected in AntD Admin is an Information Disclosure issue that arises from deficient access control measures. This oversight allows unauthorized individuals to exploit front-end interfaces, leading to potential compromise of sensitive data. Such vulnerabilities can have profound effects, particularly when personal data, like user IDs, emails, and contact information, are compromised. Information Disclosure vulnerabilities highlight the critical nature of implementing robust, centralized access control systems. The severity of this vulnerability underscores the need for vigilant monitoring of access control implementations.

Technically, the vulnerability manifests in the form of inadequate restrictions on API endpoints, such as '/api/v1/users'. Unauthorized users can access this endpoint and retrieve sensitive data formatted in JSON, including elements like user IDs and contact information. The API responds with a HTTP 200 status and a content type of 'application/json', which confirms the presence of this vulnerability. The failure to enforce proper access restrictions at the API level represents a significant security oversight in the AntD Admin interface. Such vulnerabilities demand immediate attention to avoid unauthorized data exposure.

If exploited, this Information Disclosure vulnerability can lead to unauthorized exposure of sensitive data. Malicious actors may leverage this access to compile dossiers on users, leading to potential reputational damage and privacy breaches. Such data exposure can pave the way for targeted attacks, phishing campaigns, and unauthorized impersonation efforts. Organizations may face significant legal repercussions and loss of consumer trust. It is essential to address this vulnerability promptly to protect user privacy and organizational integrity.

REFERENCES

Solution Advice
  • Update to the latest version of AntD Admin to address access control vulnerabilities.
  • Implement robust access control measures on API endpoints to restrict unauthorized access.
  • Regularly audit and test the security policies implemented in front-end interfaces.
  • Deploy monitoring solutions to detect and alert on unauthorized data access attempts.
  • Conduct user training on the importance of data privacy and secure sharing practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-46371 Scanner - Information Disclosure vulnerability in AntD Admin | S4E