$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Team collaboration platform with RBAC (Owner/Admin/Member) and invitation system. Solution: IDOR on /org/{id}/team leaked user emails across organizations, then weak passwords ({username}123) allowed login as Owner to access admin dashboard.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar