webProeasy
Lab 112 — MetricFlow — IDOR in Usage Analytics API
hackadvisor
Task: MetricFlow analytics API accepts userId as query parameter without authorization checks. Solution: enumerate user IDs from team page, change userId from 2 to 1 in API request to access admin's private usage events containing the flag.
$ ls tags/ techniques/
idor_exploitationparameter_tamperingjavascript_source_analysisuser_id_enumeration
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]MetricFlow — DOM XSS via Prototype Pollution Gadget— hackadvisor
- [web][Pro]Lab 251 — PulseBoard — IDOR via Unauthenticated GraphQL User Profile Query— hackadvisor
- [web][Pro]Lab 109 — TaskForge — IDOR in Account Settings API— hackadvisor
- [web][Pro]Lab 116 — InsightForge — IDOR via Undocumented Internal API— hackadvisor
- [web][Pro]Lab 115 — PulseChat — IDOR in Attachment Download— hackadvisor