$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Multi-tenant team collaboration platform with Owner/Admin/Member RBAC; given Member account. Solution: IDOR on /org/{id}/team leaked all user emails and roles cross-org, then guessed Owner password (alex123) to access security settings containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar