webProeasy

Lab 99 — CashPilot — IDOR in Team Member Management

hackadvisor

Task: CashPilot team management API lets admins invite users with account and role fields in the request body. Solution: tamper account_id from 2 to 1 and create an Admin user in the target account, then read the production API key.

$ ls tags/ techniques/
idor_exploitationprivilege_escalationparameter_tamperingsensitive_data_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups