$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: analytics platform with React SPA, documented API properly enforces report ownership. Solution: discover undocumented /api/internal/reports/:id endpoint that bypasses authorization, enumerate sequential report IDs to access admin's confidential audit report containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar