Delete Component watching for All Bugzilla Accounts in Mozilla(Indirect Object reference)

Company Information : 


Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements current and anticipated web standards.

Bug Title : Delete Component watching for All Bugzilla Accounts in Mozilla(Indirect Object reference)

Bug type : Indirect object reference(IDOR)

Category : Broken authentication and privilege escalation

OWASP Link : https://www.owasp.org/index.php/Top_10_2013-A4-Insecure_Direct_Object_References

Organization : Mozilla

Web Application Link : https://bugzilla.mozilla.org/

Description : In Developers Bugzilla account you have option of Component watching feature where you can save your preference of bug watch.

Exact link : https://bugzilla.mozilla.org/userprefs.cgi?tab=component_watch

When you save the component watch it is saved with a ID.Now when delete it ,The vulnerable HTTP request will delete the Component watch ID .You can change the component ID and delete any user's Component.By running script you can delete all user's component watch.

Video POC link: https://www.dropbox.com/sc/b581mjcf95gbmek/AAC4OBJtn2Aol8HdGg7bCZpTa


Mozilla fixed a issue within a Day and rewarded within few days.

Reward : 2000$

Thanks for reading.


Comments

Popular posts from this blog

Account Takeover Apple App Store Connect Account of Any user and Steal Developer API/Subscription Keys of any user(CORS+XSS) worth 8500$

Amazon Web Services : Takeover Workbook and delete the Owner on https://builder.honeycode.aws by collaborator user (IDOR) worth 7200$

UnAuth Access to Twitter Private Tweets and messages Media Content Access(IDOR)