|
|
|
|
|
by streetfighter64
106 days ago
|
|
Well, admins (or anybody other than the developers / deployment pipeline) having permissions to alter the JS sounds like a significant vulnerability. Maybe it wasn't in the early 2000s, but unencrypted HTTP was also normal then. |
|
The account in question had "staff" rights which gave him basically all rights on all wikis.