Github repo's wiki publicly editable

Disclosed: 2020-01-31 13:19:27 By whitehat_hacker To nextcloud
Unknown
Vulnerability Details
Hello Team, Github repo's wiki page is publicly editable. This enables an attacker to edit the wiki pages of the affected repo's. Adding content that may link to malicious code libraries that would be installed and used by developers or information that may mislead users. **POC link** https://github.com/nextcloud/news-android/wiki https://github.com/nextcloud/Android-SingleSignOn/wiki https://github.com/nextcloud/weather/wiki ## Impact This enables an attacker to edit the wiki pages of the affected repo's. Adding content that may link to malicious code libraries that would be installed and used by developers or information that may mislead users. Thank you.
Actions
View on HackerOne
Report Stats
  • Report ID: 475114
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report