webProeasy
Lab 109 — TaskForge — IDOR in Account Settings API
hackadvisor
Task: an account settings page exposed a client-controlled userId used by the API. Solution: tamper with the userId parameter to request the admin account and extract the flag from its api_key.
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]TeamForge — IDOR to Owner Account Takeover via Weak Passwords— hackadvisor
- [web][Pro]Lab 116 — InsightForge — IDOR via Undocumented Internal API— hackadvisor
- [web][Pro]Lab 99 — CashPilot — IDOR in Team Member Management— hackadvisor
- [web][Pro]Lab 259 — TalentBridge — IDOR in Employee Profile Endpoints— hackadvisor
- [web][Pro]Lab 112 — MetricFlow — IDOR in Usage Analytics API— hackadvisor