webPromedium

Lab 303 — DevGateway — Broken Access Control in Admin API

hackadvisor

Task: API management platform with exposed documentation revealing admin endpoints. Solution: Authenticated as regular user, accessed admin settings endpoint due to missing role-based authorization, retrieved flag from internal API secret.

$ ls tags/ techniques/
jwt_authenticationauthorization_bypassapi_endpoint_enumerationbola_exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups