Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354904b55625c433056b1c8d684462527c040881bb3b
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /api/Log/DeleteMerchantLogs GET /api/Billing/GetBillingPresetList GET /api/Billing/GetBillingSettingList GET /api/Billing/GetBillingSettingListCount GET /api/Billing/GetFulfillmentReport GET /api/Billing/GetInvoiceDetails GET /api/Billing/GetInvoiceList GET /api/Billing/GetTotalInvoiceListCount GET /api/Billing/PriceList/Get GET /api/Billing/PriceList/GetPriceListTotal GET /api/Billing/Region/GetAllListTotal GET /api/Billing/Region/GetList GET /api/BillingV2/GetBillingCategoryTypeList GET /api/BillingV2/GetBillingReportFile GET /api/BillingV2/GetBillingReportList GET /api/BillingV2/GetBillingReportListCount GET /api/BillingV2/GetBillingSettings GET /api/BillingV2/GetBillingSettingsKeyList GET /api/Document/GetInvoice GET /api/Document/GetShippingLabel GET /api/Fulfillment/CheckPickingList GET /api/Fulfillment/GetInPickingTray GET /api/Fulfillment/GetOrderItemsByPickingListId GET /api/Fulfillment/GetOrdersPickingList GET /api/Fulfillment/GetShippingProvider GET /api/Inbound/GetInboundTrackingNo GET /api/Inbound/GetItemGroups GET /api/Inbound/GetItems GET /api/Inbound/GetRequests GET /api/Inbound/GetTotalItemsCount GET /api/Inbound/GetTotalRequestsCount GET /api/Jobs/GetFile GET /api/Jobs/GetJobList GET /api/Jobs/GetJobListTotal GET /api/Jobs/GetJobStatus GET /api/Jobs/QueryJobStatus GET /api/Listing/GetListingList GET /api/Listing/GetListingListCount GET /api/Listing/GetMapping GET /api/Log/GetInboundLog GET /api/Log/GetMerchantLogs GET /api/Log/GetPerformanceLogSettings GET /api/Log/GetProductStockLog GET /api/Log/GetProductStockLogTotal GET /api/Merchant/GetAllMerchantList GET /api/Merchant/GetMerchant GET /api/Merchant/GetMerchantGroupList GET /api/Merchant/GetMerchantList GET /api/Merchant/GetMerchantListCount GET /api/Merchant/GetUnusableStockMerchantList GET /api/Notification/GetNotifications GET /api/Notification/GetNotificationsCount GET /api/Notification/GetSettings GET /api/Notification/ProductExpiry/GetSettings GET /api/Order/GetOrder GET /api/Order/GetOrderItem GET /api/Order/GetOrderItemList GET /api/Order/GetOrderList GET /api/Order/GetOrderListBySku GET /api/Order/GetOrderListCount GET /api/Order/GetOrders GET /api/Order/MerchantGetOrder GET /api/Order/MerchantGetOrderByReferenceCode GET /api/Order/OrderAttachment/Get GET /api/Outbound/GetOutboundItems GET /api/Outbound/GetOutboundRequests GET /api/Outbound/GetTotalItemsCount GET /api/Outbound/GetTotalRequestsCount GET /api/PickJob/GetPickerUserList GET /api/Product/GetBatchList GET /api/Product/GetProductList GET /api/Product/GetProductListCount GET /api/Product/GetProductStockList GET /api/Product/GetProductStockListCount GET /api/Product/Merchant/GetProductList GET /api/ShippingProvider/GetParcelDimension GET /api/ShippingProvider/GetShippingProviderList GET /api/ShippingProvider/Master/GetAll GET /api/ShippingProvider/Master/GetAllCount GET /api/Shop/AuthMarketUrl GET /api/Shop/GetShopList GET /api/Shop/GetWebhookListByShopId GET /api/Shop/SyncMarket GET /api/Statistics/GetOrder GET /api/Statistics/GetTodayDeliver GET /api/Statistics/GetTopProducts GET /api/Statistics/GetTopShops GET /api/Stock/AutoSegregation/GetAll GET /api/Stock/DisableMarketStockSync/GetList GET /api/Stock/DisableMarketStockSync/GetListCount GET /api/Stock/GetStockAlertSettingsList GET /api/Stock/GetStockBatchInfoList GET /api/Stock/GetStockBatchInfoListCount GET /api/Stock/GetStockByProduct GET /api/Stock/GetStockByProductList GET /api/Stock/GetStockByProductListCount GET /api/Stock/GetStockMovementList GET /api/Stock/GetStockMovementListCount GET /api/Stock/GetStockRebalanceList GET /api/Stock/GetStockRebalanceListCount GET /api/Stock/GetUnusableStockByProductList GET /api/Stock/GetUnusableStockByProductListCount GET /api/Stock/StockBalanceList/GetAll GET /api/Stock/StockBalanceList/GetAllTotal GET /api/StockDistribution/AutoSegregation/GetAll GET /api/StockDistribution/GetStockDistributionType GET /api/Timestamp GET /api/User/GetList GET /api/User/GetListTotal GET /api/Warehouse/Cell/GetAll GET /api/Warehouse/Cell/GetAllBySku GET /api/Warehouse/Cell/GetAllTotal GET /api/Warehouse/CellGroup/GetAll GET /api/Warehouse/CellGroup/GetAllTotal GET /api/Warehouse/GetExternalWarehouseList GET /api/Warehouse/GetExternalWarehouseMappingByMerchant GET /api/Warehouse/GetExternalWarehouseMappingList GET /api/Warehouse/GetTotalExternalWarehouseMappingListCount GET /api/Warehouse/ShippingBin/GetAll GET /api/Warehouse/ShippingBin/GetAllDetail GET /api/Warehouse/ShippingCheckoutDetail GET /api/Warehouse/VerifyTrackingNumber GET /api/Warehouse/WarehouseLocation/GetAll GET /api/Warehouse/WarehouseLocation/GetAllTotal GET /error GET /external/marketplace/easystore/authcode GET /external/marketplace/lazada/authcode GET /external/marketplace/shopee/authcode GET /external/marketplace/shopeeglobal/authcode GET /external/marketplace/shopify/authcode GET /external/marketplace/tiktokshop/authcode POST /api/Billing/BillingSetting/AutoCreate POST /api/Billing/BillingSetting/Update POST /api/Billing/PriceList/Create POST /api/Billing/Region/Create POST /api/Billing/Region/Update POST /api/BillingV2/CreateBillingSettings POST /api/BillingV2/UpdateBillingSettings POST /api/CaEwms/GetAccessToken POST /api/Fulfillment/GeneratePickingList POST /api/Fulfillment/PrintPickingList POST /api/Inbound/CreateItemQC POST /api/Inbound/CreateRequest POST /api/Inbound/CreateReturnRequest POST /api/Inbound/MerchantCreateInboundRequest POST /api/Jobs/CreateJob POST /api/Jobs/CreateJobWithAttachment POST /api/Listing/CreateMapping POST /api/Listing/DeleteMapping POST /api/Listing/ListingSync POST /api/Listing/UpdateListing POST /api/Log/AddOrEditSettings POST /api/Merchant/Create POST /api/Merchant/CreateMerchantGroup POST /api/Notification/AddOrEditSettings POST /api/Notification/MarkAsRead POST /api/Notification/RemoveSettings POST /api/Notification/SendMessageToUser POST /api/Order/ChangeToPack POST /api/Order/ChangeToReadyToShip POST /api/Order/Internal/CreateOrder POST /api/Order/LogisticPriceCheck POST /api/Order/MerchantCreateOrder POST /api/Order/OrderAttachment/Create POST /api/Order/SyncMarketPlaceOrder POST /api/Outbound/CreateOutboundItemQc POST /api/Outbound/CreateOutboundRequest POST /api/Outbound/UpdateOutboundRequestStatus POST /api/PickJob/CreatePickJob POST /api/PickJob/ReprocessPickJob POST /api/Product/CreateProduct POST /api/ShippingProvider/Master/Create POST /api/ShippingProvider/Master/Status POST /api/ShippingProvider/Master/Update POST /api/ShippingProvider/Merchant/Assign POST /api/ShippingProvider/Merchant/Unassign POST /api/Shop/AddOrUpdateWebhook POST /api/Shop/Create POST /api/Shop/GetAccessToken POST /api/Shop/RemoveWebhook POST /api/Shop/Update POST /api/Stock/AdjustOutboundStockSync POST /api/Stock/AdjustStockSync POST /api/Stock/AdjustStocks POST /api/Stock/AssignStockSync POST /api/Stock/AutoSegregation/Create POST /api/Stock/CancelOrder POST /api/Stock/CreateStockAlertSettings POST /api/Stock/CreateStockMovement POST /api/Stock/DisableMarketStockSync/Create POST /api/Stock/DisableMarketStockSync/Delete POST /api/Stock/GetOutboundProductQuantity POST /api/Stock/ManualStocksRebalance POST /api/Stock/QuantitySync POST /api/Stock/QuantitySync/ByProducts POST /api/Stock/StockIn POST /api/Stock/StockSegregation/BulkSync POST /api/Stock/SyncMarketProductStock POST /api/Stock/UpdateStockAlertSettings POST /api/StockDistribution/AddOrEditSettings POST /api/StockDistribution/GetBufferStockSetting POST /api/User/Authenticate POST /api/User/Create POST /api/User/ForgetPassword POST /api/User/Myself POST /api/User/ResetPassword POST /api/User/Update POST /api/User/Update/Password POST /api/Warehouse/Cell/Create POST /api/Warehouse/Cell/Update POST /api/Warehouse/CellGroup/Create POST /api/Warehouse/CreateExternalWarehouseMapping POST /api/Warehouse/GetWarehouseDetails POST /api/Warehouse/ShippingBin/CompleteDelivery POST /api/Warehouse/ShippingBinList/Create POST /api/Warehouse/UpdateExternalWarehouseMapping POST /api/Warehouse/UpdateWarehouseDetails POST /api/Webhook/aftership/tracking POST /api/Webhook/ewmsv2/pickjobstatus POST /api/Webhook/shippop/tracking POST /external/marketplace/lazada/webhook POST /external/marketplace/shopee/webhook POST /external/marketplace/shopify/fulfillment_order_notification POST /external/marketplace/tiktokshop/webhook POST /external/marketplace/zalora/webhook POST /external/warehouse/ReleaseBucket POST /external/warehouse/pingspace/webhook PUT /api/Billing/Invoice/Update PUT /api/Billing/PriceList/Update PUT /api/Billing/Region/Postcodes/Update PUT /api/Fulfillment/ChangeToPick PUT /api/Fulfillment/ClearPickingList PUT /api/Fulfillment/UpdateOrdersPickingList PUT /api/Inbound/UpdateInboundTrackingNo PUT /api/Inbound/UpdateItemGroupStatuses PUT /api/Inbound/UpdateRequestStatus PUT /api/Merchant/Update PUT /api/Merchant/UpdateMerchantGroup PUT /api/Order/EnterTrackingNo PUT /api/Order/UpdateBoxSize PUT /api/Order/UpdateFinalWeight PUT /api/Order/UpdateOrder PUT /api/Product/UpdateProduct PUT /api/Product/UpdateProductStatus PUT /api/ShippingProvider/Confirm PUT /api/Stock/AutoSegregation/Update PUT /api/Stock/DisableMarketStockSync/Update PUT /api/Stock/ReProcessOrder PUT /api/Stock/StockBalanceList/Update PUT /api/User/Update/RoleStatus PUT /api/Warehouse/CellGroup/Update PUT /api/Warehouse/WarehouseLocation/Update
Open service 20.212.64.8:443 ยท stagingapi-ewms.commerce.asia
2026-01-22 11:56
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Thu, 22 Jan 2026 11:57:12 GMT Server: Microsoft-IIS/10.0 Location: /swagger Set-Cookie: ARRAffinity=04c71defa120a70108b1569df6fd4a577f2d4830524c087bf7271fa750e88c4e;Path=/;HttpOnly;Secure;Domain=stagingapi-ewms.commerce.asia Set-Cookie: ARRAffinitySameSite=04c71defa120a70108b1569df6fd4a577f2d4830524c087bf7271fa750e88c4e;Path=/;HttpOnly;SameSite=None;Secure;Domain=stagingapi-ewms.commerce.asia X-Powered-By: ASP.NET