id: smtp4dev-interface-exposed info: name: SMTP4Dev Interface - Exposed author: DhiyaneshDk severity: high description: | Publicly exposed smtp4dev interface allowing access to intercepted emails and test configurations. metadata: verified: true max-request: 1 shodan-query: title:"smtp4dev" tags: smtp4dev,misconfig,exposure,mail,interface http: - method: GET path: - "{{BaseURL}}" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - "