Security misconfiguration

Perfectly secure software, deployed with the wrong settings, is not secure.

The defaults are frequently permissive because that makes things work out of the box: debug pages enabled, sample accounts left in place, storage readable by anybody with the address, verbose errors printing internals. Nothing was exploited. Somebody simply left a door on the latch, and often the person deploying it did not know the door existed.

Checked against the primary source.

More on Application security