0xIncaInsider
HomeBlogArchivesTagsCollectionsAbout
← Writeups
·

User ID controlled by request parameter

https://portswigger.net/web-security/access-control/lab-user-id-controlled-by-request-parameter

This lab has a horizontal privilege escalation vulnerability on the user account page.

To solve the lab, obtain the API key for the user carlos and submit it as the solution.

You can log in to your own account using the following credentials: wiener:peter


cambiar el parametro id a carlos

// 0xIncaInsider — offensive security research