webProeasy

Lab 110 — FlowDesk — Mass Assignment Privilege Escalation

hackadvisor

Task: team collaboration platform with REST API exposing role field in user profile response. Solution: exploit mass assignment by adding role=admin to profile update request, bypassing frontend restrictions to gain admin access.

$ ls tags/ techniques/
role_escalationapi_parameter_tamperingmass_assignment_exploitationhidden_field_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups