webProeasy

Lab 291 — HireFlow — Broken Authorization in Premium Feature Endpoints

hackadvisor

Task: Recruitment platform with Free/Professional/Enterprise tiers, premium features locked in UI. Solution: Discovered API endpoints in settings page, directly called premium endpoints bypassing client-side restrictions to access confidential reports containing the flag.

$ ls tags/ techniques/
api_endpoint_enumerationdirect_api_accesssubscription_tier_bypassdecoy_flag_recognition

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups