arrow-down arrow at-sign bug check checkbox-checked checkbox-unchecked svg-checkmark chevron-right chevrons-right circle-down circle-left circle-right circle-up cloud2 svg-cross2 download download external-link filter github hash home leaf leaf left link-2 log-in log-out mail menu message-square minus plus radio-checked radio-checked2 radio-unchecked search settings spinner8 target twitter up upload-2 user users warning x zap
  • Home
  • Report a bug
  • Contribute
  • All issues
  • Login

URL: https://wiki.mozilla.org/

Browser / Version: Chrome 83.0.4103
Operating System: Linux
Tested Another Browser: Yes Chrome

Problem type: Something else
Description: Privilage escalation using default password
Steps to Reproduce:
Hello Mozill security Team.
During my bug hunting on mozilla.org site.
I found wiki.mozilla.org. This site doesn't allow anonymous users to get admin level access to edit pages. Only the invited or rquested account which has got permission can create account and edit the pages.

I tried to request an account of myself since it doesn't have registration page. I found that my registration request has been purged because of anonymous user requesting for an account.

So i tried to login to the site using default credentials.
Suddenly, I was able to access the higher privilege level that allowed me to edit the webpages, add images etc.

Impact of this issue.

This is a critical issue for Mozilla foundation.
i). An attacker might would have defaced the website.
ii). Any body can edit the webpages and addd explicit, pornographic content, use this website for phishing website leading to massive account takeover.
iii) Delivery of malware,virus, infected mozilla products etc
iv). And An attacker may have ruined the reputation of mozilla foundation.

I hope Security team to have great concern towards this issue.

For the confirmation.
i have edited the webpage https://wiki.mozilla.org/Releases
and added phishing-site.com instead of original site added by admin.

And i have also added an image depicting defaced website.

Three POC have been submitted in order to confirm the BUG.

If you want i will securely deliver the credentials i used to deface the site.

For contact: I am adding my hackerone profile URL
hackerone: https://hackerone.com/aaryan9898?type=user
My original-email : Mahtoshivnath07gmail.com
email-used-while-submitting-bug: Mahtoshivnath702@gmail.com
twitter: https://twitter.com/Aaryan076?s=01
For more information related to bug.
Contact me on above mentioned addresses.

Thank you.
I hope mozilla security team would look into this issue as soon as possible.

View the screenshot Screenshot
Browser Configuration
  • None

From webcompat.com with ❤️

Please login to edit issues.

View issue on Github

Shortcut: Press l on your keyboard to open the label editor. Shortcut: Press g on your keyboard to be taken to the GitHub view of this page.
Closed: Duplicate
#60865

wiki.mozilla.org - Privilage escalation using default password

Opened: 2020-11-01
Reporter: r3dpars3c
Comments: 2
  • Home
  • List of issues
  • About
  • Contribute
  • Contact
  • Privacy Policy
  • Terms of Service
  • Code of Conduct