GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d63e930952d0dcbfa2c8ff28f32b970d8457008d26
GraphQL introspection enabled at /api/graphql Types: 600 (by kind: ENUM: 58, INPUT_OBJECT: 144, INTERFACE: 30, OBJECT: 363, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d63e930952d0dcbfa2c8ff28f32b970d848a2919d5
GraphQL introspection enabled at /api/graphql Types: 600 (by kind: ENUM: 58, INPUT_OBJECT: 144, INTERFACE: 30, OBJECT: 363, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Open service 151.101.131.10:443 · stage.ibcmed.com
2026-01-22 20:57
HTTP/1.1 401 Unauthorized Connection: close Content-Length: 381 x-frame-options: SAMEORIGIN www-authenticate: Basic realm="Authentication Required" content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Thu, 22 Jan 2026 20:57:33 GMT Strict-Transport-Security: max-age=31557600 set-cookie: affinity="396e15d88da9e1e2"; Path=/; HttpOnly; secure X-Served-By: cache-rtm-ehrd2290044-RTM X-Cache: MISS X-Timer: S1769115453.923605,VS0,VS0,VE196 Page title: 401 Unauthorized <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>401 Unauthorized</title> </head><body> <h1>Unauthorized</h1> <p>This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required.</p> </body></html>
Open service 151.101.131.10:443 · stage.ibcmed.com
2026-01-08 19:37
HTTP/1.1 401 Unauthorized Connection: close Content-Length: 381 x-frame-options: SAMEORIGIN www-authenticate: Basic realm="Authentication Required" content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Thu, 08 Jan 2026 19:37:13 GMT Strict-Transport-Security: max-age=31557600 set-cookie: affinity="c61b233a3a66e535"; Path=/; HttpOnly; secure X-Served-By: cache-lcy-egml8630023-LCY X-Cache: MISS X-Timer: S1767901033.383559,VS0,VS0,VE440 Page title: 401 Unauthorized <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>401 Unauthorized</title> </head><body> <h1>Unauthorized</h1> <p>This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required.</p> </body></html>
Open service 151.101.131.10:443 · stage.ibcmed.com
2025-12-22 22:09
HTTP/1.1 401 Unauthorized Connection: close Content-Length: 381 x-frame-options: SAMEORIGIN www-authenticate: Basic realm="Authentication Required" content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Mon, 22 Dec 2025 22:09:17 GMT Strict-Transport-Security: max-age=31557600 set-cookie: affinity="93cb2e919c154290"; Path=/; HttpOnly; secure X-Served-By: cache-bom-vanm7210060-BOM X-Cache: MISS X-Timer: S1766441357.970154,VS0,VS0,VE229 Page title: 401 Unauthorized <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>401 Unauthorized</title> </head><body> <h1>Unauthorized</h1> <p>This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required.</p> </body></html>