$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Payment platform with GraphQL API and role-based access (admin/finance/viewer), given finance credentials. Solution: Used GraphQL introspection to discover admin-only queries, then exploited missing resolver-level authorization to access adminConfig containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar