GitHub users outside of HackerOne organization can create and update Wiki pages of certain public HackerOne repositories
None
Vulnerability Details
**Summary**
Hi HackerOne team,
recently this vulnerability have been reported and resolved in various programs, so I'm going to try my bad luck, reporting the same kind of report also in this program.
**Steps**
1. Go on https://github.com/Hacker0x01/react-datepicker/wiki/BB-test
2. I've created a simple page in the wiki without be a collaborator of the repo, or and without any permission
3. Going on https://github.com/Hacker0x01/react-datepicker/wiki/ you can add a new `fake` or `phishing` page clicking on the `New page` or `edit` buttons.
4. {F388246}
**PS**
First of all,
I'm not sure that this type of issue is allowed on your program, but seeing the following report (https://hackerone.com/reports/457009) seem that is quite accepted by anyone, so I will try my luck (I'm going to fail, I know lol).
I know also that the impact isn't interesting, but as I said previously, let me try :)
## Impact
Add and edit pages in the `wiki` of the https://github.com/Hacker0x01/react-datepicker/ repo
Actions
View on HackerOneReport Stats
- Report ID: 459634
- State: Closed
- Substate: resolved
- Upvotes: 12