Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e560adb0b47655e17ac49aefe425a85cdad7ab8f9f
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths: GET / GET /adjust GET /api/data-manager/execute GET /mail POST /aliloan/v1/order/apply POST /aliloan/v1/order/calculate POST /aliloan/v1/order/deferPay POST /aliloan/v1/order/modifyBankCard POST /aliloan/v1/order/precheck POST /aliloan/v1/order/queryById POST /aliloan/v1/pay/orderRepay POST /aliloan/v1/product/getById POST /api/v3/app/channel POST /api/v3/app/config POST /api/v3/app/home POST /api/v3/app/settings POST /api/v3/auth/close POST /api/v3/auth/login POST /api/v3/auth/logout POST /api/v3/auth/registerOrLogin POST /api/v3/auth/singleLogin POST /api/v3/bankcard/list POST /api/v3/bankcard/modify POST /api/v3/bury/homePage POST /api/v3/bury/record POST /api/v3/category/gory POST /api/v3/hire/collect/mail POST /api/v3/kyc/commit POST /api/v3/kyc/init POST /api/v3/kyc/item/commit POST /api/v3/kyc/item/init POST /api/v3/kyc/liveness/silent POST /api/v3/kyc/status POST /api/v3/mobile/contact POST /api/v3/mobile/contactBackup POST /api/v3/mobile/device POST /api/v3/mobile/device/extend POST /api/v3/mobile/registerDevice POST /api/v3/order/apply POST /api/v3/order/apply/withdrawal POST /api/v3/order/detail POST /api/v3/order/detailV2 POST /api/v3/order/getAddressList POST /api/v3/order/getArsLink POST /api/v3/order/h5AllApply POST /api/v3/order/h5UserSubmit POST /api/v3/order/h5UserSubmitV2 POST /api/v3/order/h5UserSubmitV2New POST /api/v3/order/h5UserSubmitV3 POST /api/v3/order/list POST /api/v3/order/ready POST /api/v3/order/repay/connect POST /api/v3/order/repay/connectBatch POST /api/v3/order/repay/extension POST /api/v3/order/repay/extensionBatch POST /api/v3/order/userSubmit POST /api/v3/order/userSubmitOutstanding POST /api/v3/order/withdrawn/detail POST /api/v3/payAccountInfo/list POST /api/v3/payAccountInfo/payAccountItemList POST /api/v3/payAccountInfo/save POST /api/v3/payAccountInfo/update POST /api/v3/personal/supp POST /api/v3/product/h5TermAllV2 POST /api/v3/product/list POST /api/v3/product/listEcx POST /api/v3/product/listOutstanding POST /api/v3/product/listV2 POST /api/v3/product/state POST /api/v3/product/term POST /api/v3/product/termAll POST /api/v3/product/termArtemis POST /api/v3/product/termV2 POST /api/v3/product/termV2New POST /api/v3/sms/sendVerifySms POST /api/v3/sys/bank POST /api/v3/sys/city POST /api/v3/sys/ifsc POST /api/v3/sys/province POST /api/v3/sys/upload POST /api/v3/sys/wallet POST /api/v3/user/carouselData POST /api/v3/user/desire POST /api/v3/user/h5Home POST /api/v3/user/h5Suphome POST /api/v3/user/home POST /api/v3/user/info POST /api/v3/user/problemFeedback POST /api/v3/user/problemFeedbackGame POST /api/v3/user/problemFeedbackQuery POST /api/v3/user/reason POST /api/v3/vayHub/login POST /app/v3/app/appCountry POST /app/v3/app/appFileConfig POST /app/v3/app/channel POST /app/v3/app/config POST /app/v3/app/home POST /app/v3/app/settings POST /app/v3/app/version POST /app/v3/app/versionV2 POST /app/v3/auth/close POST /app/v3/auth/logout POST /app/v3/auth/registerOrLogin POST /app/v3/bankcard/collection POST /app/v3/bankcard/indiabank POST /app/v3/bankcard/indiabankinfo POST /app/v3/bankcard/list POST /app/v3/bankcard/modify POST /app/v3/bankcard/myindiabank POST /app/v3/bury/record POST /app/v3/bury/variable POST /app/v3/category/gory POST /app/v3/kyc/commit POST /app/v3/kyc/four/contact POST /app/v3/kyc/four/liveness POST /app/v3/kyc/four/personal POST /app/v3/kyc/four/search-iterm POST /app/v3/kyc/four/status POST /app/v3/kyc/four/work POST /app/v3/kyc/init POST /app/v3/kyc/item/commit POST /app/v3/kyc/item/init POST /app/v3/kyc/liveness/advance/detection POST /app/v3/kyc/liveness/advance/license POST /app/v3/kyc/liveness/cloudun/silent POST /app/v3/kyc/liveness/dynamic POST /app/v3/kyc/liveness/silent POST /app/v3/kyc/liveness/surfinlab/detection POST /app/v3/kyc/status POST /app/v3/mentation/findmentation POST /app/v3/mobile/appUsageStatistics POST /app/v3/mobile/calendar POST /app/v3/mobile/callRecord POST /app/v3/mobile/contact POST /app/v3/mobile/contactBackup POST /app/v3/mobile/device POST /app/v3/mobile/getAddressBookBackup POST /app/v3/mobile/installApp POST /app/v3/mobile/photo POST /app/v3/mobile/registerDevice POST /app/v3/mobile/riskExtendInfo POST /app/v3/mobile/setAddressBookBackup POST /app/v3/mobile/sms POST /app/v3/notify/list POST /app/v3/order/apply POST /app/v3/order/apply/withdrawal POST /app/v3/order/autoOrderApply POST /app/v3/order/detail POST /app/v3/order/detailV2 POST /app/v3/order/list POST /app/v3/order/ready POST /app/v3/order/repay/connect POST /app/v3/order/repay/connectBatch POST /app/v3/order/repay/extension POST /app/v3/order/repay/extensionBatch POST /app/v3/order/repayWilling/sure POST /app/v3/order/submit POST /app/v3/order/userSubmit POST /app/v3/order/userSubmitArtemis POST /app/v3/order/userSubmitOutstanding POST /app/v3/order/userSubmitV2 POST /app/v3/order/userSubmitV2Map POST /app/v3/order/userSubmitV2New POST /app/v3/order/userSubmitV2NewMap POST /app/v3/order/userSubmitV3 POST /app/v3/order/withdrawn/detail POST /app/v3/payAccountInfo/list POST /app/v3/payAccountInfo/payAccountItemList POST /app/v3/payAccountInfo/save POST /app/v3/payAccountInfo/update POST /app/v3/personal/supp POST /app/v3/product/amount POST /app/v3/product/list POST /app/v3/product/listEcx POST /app/v3/product/listOutstanding POST /app/v3/product/listV2 POST /app/v3/product/state POST /app/v3/product/term POST /app/v3/product/termArtemis POST /app/v3/product/termV2 POST /app/v3/product/termV2Map POST /app/v3/product/termV2New POST /app/v3/product/termV2NewMap POST /app/v3/product/termV3 POST /app/v3/product/trial POST /app/v3/sms/sendVerifySms POST /app/v3/sys/bank POST /app/v3/sys/city POST /app/v3/sys/ifsc POST /app/v3/sys/province POST /app/v3/sys/upload POST /app/v3/sys/wallet POST /app/v3/sys/ward POST /app/v3/user/carouselData POST /app/v3/user/demand POST /app/v3/user/desire POST /app/v3/user/home POST /app/v3/user/homePage POST /app/v3/user/info POST /app/v3/user/problemFeedback POST /app/v3/user/problemFeedbackQuery POST /app/v3/user/reason POST /app/v3/user/signIn POST /app/v3/user/suphome POST /app/v3/vayHub/forgetPassword POST /app/v3/vayHub/getotp POST /app/v3/vayHub/login POST /cactus/v1/bank/bind POST /cactus/v1/laon/repaymentDetails POST /cactus/v1/loan/details POST /cactus/v1/order/baseInfo POST /cactus/v1/order/batchConclusion POST /cactus/v1/order/batchOrderStatus POST /cactus/v1/order/batchRepaymentPlan POST /cactus/v1/order/changeBank POST /cactus/v1/order/conclusion POST /cactus/v1/order/deviceInfo POST /cactus/v1/order/orderStatus POST /cactus/v1/order/repaymentPlan POST /cactus/v1/product/filter POST /callback/surfin POST /callback/v1/ascoamPay/payout POST /callback/v1/ascoamPay/repay POST /callback/v1/bravo/payin/notify POST /callback/v1/bravo/payout/notify POST /callback/v1/byUserScore/getUserAmount POST /callback/v1/cadoPay/payout POST /callback/v1/cadoPay/repay POST /callback/v1/cadoPayPhilippines/payout POST /callback/v1/cadoPayPhilippines/repay POST /callback/v1/coinpay/payin/notify POST /callback/v1/coinpay/payout/notify POST /callback/v1/easypay/payin/notify POST /callback/v1/easypay/payout/notify POST /callback/v1/expay/payout/notify POST /callback/v1/expay/repay/notify POST /callback/v1/hipay/payout/notify POST /callback/v1/hipay/repay/notify POST /callback/v1/hpay/payin/notify POST /callback/v1/hpay/payout/notify POST /callback/v1/hxpay/payin/notify POST /callback/v1/hxpay/payout/notify POST /callback/v1/icepay/payin/notify POST /callback/v1/icepay/payout/notify POST /callback/v1/inpay/payin/notify POST /callback/v1/inpay/payout/notify POST /callback/v1/jjpay/payin/notify POST /callback/v1/jjpay/payout/notify POST /callback/v1/kxypay/payout/notify POST /callback/v1/kxypay/repay/notify POST /callback/v1/landlordPay/payin/notify POST /callback/v1/landlordPay/payout/notify POST /callback/v1/mangocoinPay/payin/notify POST /callback/v1/mangocoinPay/payin/notifyArs POST /callback/v1/mangocoinPay/payout/notify POST /callback/v1/mangocoinPay/payout/notifyArs POST /callback/v1/mwxpapay/payout/notify POST /callback/v1/mwxpapay/repay/notify POST /callback/v1/mypay/payin/notify POST /callback/v1/mypay/payout/notify POST /callback/v1/nx/cdr POST /callback/v1/oxpay/payout/notify POST /callback/v1/oxpay/repay/notify POST /callback/v1/pandapay/payout/notify POST /callback/v1/pandapay/repay/notify POST /callback/v1/paysopay/payin/notify POST /callback/v1/paysopay/payout/notify POST /callback/v1/pePay/payin/notify POST /callback/v1/pePay/payout/notify POST /callback/v1/phonepay/payin/notify POST /callback/v1/phonepay/payout/notify POST /callback/v1/qspay/payin/notify POST /callback/v1/qspay/payout/notify POST /callback/v1/risk/audit POST /callback/v1/risk/auditResult POST /callback/v1/risk/reloan POST /callback/v1/seedpay/payout POST /callback/v1/seedpay/repay POST /callback/v1/seppay/payin/notify POST /callback/v1/seppay/payout/notify POST /callback/v1/serpay/payout POST /callback/v1/serpay/repay POST /callback/v1/shivaPay/payin/notify POST /callback/v1/shivaPay/payout/notify POST /callback/v1/skypay/payout/notify POST /callback/v1/skypay/repay/notify POST /callback/v1/skypay/repay/validated POST /callback/v1/tarspay/notify POST /callback/v1/topPay/payout/notify POST /callback/v1/topPay/repay/notify POST /callback/v1/utradePay/payout/notify POST /callback/v1/utradePay/repay/notify POST /callback/v1/v5pay/payin/notify POST /callback/v1/v5pay/payout/notify POST /callback/v1/v5pay/repay/validated POST /callback/v1/vnpay/payout/notify POST /callback/v1/vnpay/repay/notify POST /callback/v1/vpay/payout/notify POST /callback/v1/vpay/payout/revoke POST /callback/v1/vpay/repay/notify POST /callback/v1/wowpay/payout/notify POST /callback/v1/wowpay/repay/notify POST /callback/v1/wzpay/payout/notify POST /callback/v1/wzpay/repay/notify POST /callback/v1/zoomPay/payin/notify POST /callback/v1/zoomPay/payout/notify
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e560adb0b47655e17ac49aefe425a85cda728a2e94
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths: GET / GET /adjust GET /api/data-manager/execute GET /mail POST /aliloan/v1/order/apply POST /aliloan/v1/order/calculate POST /aliloan/v1/order/deferPay POST /aliloan/v1/order/modifyBankCard POST /aliloan/v1/order/precheck POST /aliloan/v1/order/queryById POST /aliloan/v1/pay/orderRepay POST /aliloan/v1/product/getById POST /api/v3/app/channel POST /api/v3/app/config POST /api/v3/app/home POST /api/v3/app/settings POST /api/v3/auth/close POST /api/v3/auth/login POST /api/v3/auth/logout POST /api/v3/auth/registerOrLogin POST /api/v3/auth/singleLogin POST /api/v3/bankcard/list POST /api/v3/bankcard/modify POST /api/v3/bury/homePage POST /api/v3/bury/record POST /api/v3/category/gory POST /api/v3/hire/collect/mail POST /api/v3/kyc/commit POST /api/v3/kyc/init POST /api/v3/kyc/item/commit POST /api/v3/kyc/item/init POST /api/v3/kyc/liveness/silent POST /api/v3/kyc/status POST /api/v3/mobile/contact POST /api/v3/mobile/contactBackup POST /api/v3/mobile/device POST /api/v3/mobile/device/extend POST /api/v3/mobile/registerDevice POST /api/v3/order/apply POST /api/v3/order/apply/withdrawal POST /api/v3/order/detail POST /api/v3/order/detailV2 POST /api/v3/order/getAddressList POST /api/v3/order/getArsLink POST /api/v3/order/h5AllApply POST /api/v3/order/h5UserSubmit POST /api/v3/order/h5UserSubmitV2 POST /api/v3/order/h5UserSubmitV2New POST /api/v3/order/h5UserSubmitV3 POST /api/v3/order/list POST /api/v3/order/ready POST /api/v3/order/repay/connect POST /api/v3/order/repay/connectBatch POST /api/v3/order/repay/extension POST /api/v3/order/repay/extensionBatch POST /api/v3/order/userSubmit POST /api/v3/order/userSubmitOutstanding POST /api/v3/order/withdrawn/detail POST /api/v3/payAccountInfo/list POST /api/v3/payAccountInfo/payAccountItemList POST /api/v3/payAccountInfo/save POST /api/v3/payAccountInfo/update POST /api/v3/personal/supp POST /api/v3/product/h5TermAllV2 POST /api/v3/product/list POST /api/v3/product/listOutstanding POST /api/v3/product/listV2 POST /api/v3/product/state POST /api/v3/product/term POST /api/v3/product/termAll POST /api/v3/product/termArtemis POST /api/v3/product/termV2 POST /api/v3/product/termV2New POST /api/v3/sms/sendVerifySms POST /api/v3/sys/bank POST /api/v3/sys/city POST /api/v3/sys/ifsc POST /api/v3/sys/province POST /api/v3/sys/upload POST /api/v3/sys/wallet POST /api/v3/user/carouselData POST /api/v3/user/desire POST /api/v3/user/h5Home POST /api/v3/user/h5Suphome POST /api/v3/user/home POST /api/v3/user/info POST /api/v3/user/problemFeedback POST /api/v3/user/problemFeedbackGame POST /api/v3/user/problemFeedbackQuery POST /api/v3/user/reason POST /api/v3/vayHub/login POST /app/v3/app/appCountry POST /app/v3/app/appFileConfig POST /app/v3/app/channel POST /app/v3/app/config POST /app/v3/app/home POST /app/v3/app/settings POST /app/v3/app/version POST /app/v3/app/versionV2 POST /app/v3/auth/close POST /app/v3/auth/logout POST /app/v3/auth/registerOrLogin POST /app/v3/bankcard/collection POST /app/v3/bankcard/indiabank POST /app/v3/bankcard/indiabankinfo POST /app/v3/bankcard/list POST /app/v3/bankcard/modify POST /app/v3/bankcard/myindiabank POST /app/v3/bury/record POST /app/v3/bury/variable POST /app/v3/category/gory POST /app/v3/kyc/commit POST /app/v3/kyc/four/contact POST /app/v3/kyc/four/liveness POST /app/v3/kyc/four/personal POST /app/v3/kyc/four/search-iterm POST /app/v3/kyc/four/status POST /app/v3/kyc/four/work POST /app/v3/kyc/init POST /app/v3/kyc/item/commit POST /app/v3/kyc/item/init POST /app/v3/kyc/liveness/advance/detection POST /app/v3/kyc/liveness/advance/license POST /app/v3/kyc/liveness/cloudun/silent POST /app/v3/kyc/liveness/dynamic POST /app/v3/kyc/liveness/silent POST /app/v3/kyc/liveness/surfinlab/detection POST /app/v3/kyc/status POST /app/v3/mentation/findmentation POST /app/v3/mobile/appUsageStatistics POST /app/v3/mobile/calendar POST /app/v3/mobile/callRecord POST /app/v3/mobile/contact POST /app/v3/mobile/contactBackup POST /app/v3/mobile/device POST /app/v3/mobile/getAddressBookBackup POST /app/v3/mobile/installApp POST /app/v3/mobile/photo POST /app/v3/mobile/registerDevice POST /app/v3/mobile/riskExtendInfo POST /app/v3/mobile/setAddressBookBackup POST /app/v3/mobile/sms POST /app/v3/notify/list POST /app/v3/order/apply POST /app/v3/order/apply/withdrawal POST /app/v3/order/autoOrderApply POST /app/v3/order/detail POST /app/v3/order/detailV2 POST /app/v3/order/list POST /app/v3/order/ready POST /app/v3/order/repay/connect POST /app/v3/order/repay/connectBatch POST /app/v3/order/repay/extension POST /app/v3/order/repay/extensionBatch POST /app/v3/order/repayWilling/sure POST /app/v3/order/submit POST /app/v3/order/userSubmit POST /app/v3/order/userSubmitArtemis POST /app/v3/order/userSubmitOutstanding POST /app/v3/order/userSubmitV2 POST /app/v3/order/userSubmitV2Map POST /app/v3/order/userSubmitV2New POST /app/v3/order/userSubmitV2NewMap POST /app/v3/order/userSubmitV3 POST /app/v3/order/withdrawn/detail POST /app/v3/payAccountInfo/list POST /app/v3/payAccountInfo/payAccountItemList POST /app/v3/payAccountInfo/save POST /app/v3/payAccountInfo/update POST /app/v3/personal/supp POST /app/v3/product/amount POST /app/v3/product/list POST /app/v3/product/listOutstanding POST /app/v3/product/listV2 POST /app/v3/product/state POST /app/v3/product/term POST /app/v3/product/termArtemis POST /app/v3/product/termV2 POST /app/v3/product/termV2Map POST /app/v3/product/termV2New POST /app/v3/product/termV2NewMap POST /app/v3/product/termV3 POST /app/v3/product/trial POST /app/v3/sms/sendVerifySms POST /app/v3/sys/bank POST /app/v3/sys/city POST /app/v3/sys/ifsc POST /app/v3/sys/province POST /app/v3/sys/upload POST /app/v3/sys/wallet POST /app/v3/sys/ward POST /app/v3/user/carouselData POST /app/v3/user/demand POST /app/v3/user/desire POST /app/v3/user/home POST /app/v3/user/homePage POST /app/v3/user/info POST /app/v3/user/problemFeedback POST /app/v3/user/problemFeedbackQuery POST /app/v3/user/reason POST /app/v3/user/signIn POST /app/v3/user/suphome POST /app/v3/vayHub/forgetPassword POST /app/v3/vayHub/getotp POST /app/v3/vayHub/login POST /cactus/v1/bank/bind POST /cactus/v1/laon/repaymentDetails POST /cactus/v1/loan/details POST /cactus/v1/order/baseInfo POST /cactus/v1/order/batchConclusion POST /cactus/v1/order/batchOrderStatus POST /cactus/v1/order/batchRepaymentPlan POST /cactus/v1/order/changeBank POST /cactus/v1/order/conclusion POST /cactus/v1/order/deviceInfo POST /cactus/v1/order/orderStatus POST /cactus/v1/order/repaymentPlan POST /cactus/v1/product/filter POST /callback/surfin POST /callback/v1/ascoamPay/payout POST /callback/v1/ascoamPay/repay POST /callback/v1/bravo/payin/notify POST /callback/v1/bravo/payout/notify POST /callback/v1/byUserScore/getUserAmount POST /callback/v1/cadoPay/payout POST /callback/v1/cadoPay/repay POST /callback/v1/cadoPayPhilippines/payout POST /callback/v1/cadoPayPhilippines/repay POST /callback/v1/coinpay/payin/notify POST /callback/v1/coinpay/payout/notify POST /callback/v1/easypay/payin/notify POST /callback/v1/easypay/payout/notify POST /callback/v1/expay/payout/notify POST /callback/v1/expay/repay/notify POST /callback/v1/hipay/payout/notify POST /callback/v1/hipay/repay/notify POST /callback/v1/hpay/payin/notify POST /callback/v1/hpay/payout/notify POST /callback/v1/hxpay/payin/notify POST /callback/v1/hxpay/payout/notify POST /callback/v1/icepay/payin/notify POST /callback/v1/icepay/payout/notify POST /callback/v1/inpay/payin/notify POST /callback/v1/inpay/payout/notify POST /callback/v1/jjpay/payin/notify POST /callback/v1/jjpay/payout/notify POST /callback/v1/kxypay/payout/notify POST /callback/v1/kxypay/repay/notify POST /callback/v1/landlordPay/payin/notify POST /callback/v1/landlordPay/payout/notify POST /callback/v1/mangocoinPay/payin/notify POST /callback/v1/mangocoinPay/payin/notifyArs POST /callback/v1/mangocoinPay/payout/notify POST /callback/v1/mangocoinPay/payout/notifyArs POST /callback/v1/mwxpapay/payout/notify POST /callback/v1/mwxpapay/repay/notify POST /callback/v1/mypay/payin/notify POST /callback/v1/mypay/payout/notify POST /callback/v1/nx/cdr POST /callback/v1/oxpay/payout/notify POST /callback/v1/oxpay/repay/notify POST /callback/v1/pandapay/payout/notify POST /callback/v1/pandapay/repay/notify POST /callback/v1/paysopay/payin/notify POST /callback/v1/paysopay/payout/notify POST /callback/v1/pePay/payin/notify POST /callback/v1/pePay/payout/notify POST /callback/v1/phonepay/payin/notify POST /callback/v1/phonepay/payout/notify POST /callback/v1/qspay/payin/notify POST /callback/v1/qspay/payout/notify POST /callback/v1/risk/audit POST /callback/v1/risk/auditResult POST /callback/v1/risk/reloan POST /callback/v1/seedpay/payout POST /callback/v1/seedpay/repay POST /callback/v1/seppay/payin/notify POST /callback/v1/seppay/payout/notify POST /callback/v1/serpay/payout POST /callback/v1/serpay/repay POST /callback/v1/shivaPay/payin/notify POST /callback/v1/shivaPay/payout/notify POST /callback/v1/skypay/payout/notify POST /callback/v1/skypay/repay/notify POST /callback/v1/skypay/repay/validated POST /callback/v1/tarspay/notify POST /callback/v1/topPay/payout/notify POST /callback/v1/topPay/repay/notify POST /callback/v1/utradePay/payout/notify POST /callback/v1/utradePay/repay/notify POST /callback/v1/v5pay/payin/notify POST /callback/v1/v5pay/payout/notify POST /callback/v1/v5pay/repay/validated POST /callback/v1/vnpay/payout/notify POST /callback/v1/vnpay/repay/notify POST /callback/v1/vpay/payout/notify POST /callback/v1/vpay/payout/revoke POST /callback/v1/vpay/repay/notify POST /callback/v1/wowpay/payout/notify POST /callback/v1/wowpay/repay/notify POST /callback/v1/wzpay/payout/notify POST /callback/v1/wzpay/repay/notify POST /callback/v1/zoomPay/payin/notify POST /callback/v1/zoomPay/payout/notify