webPromedium

TeamForge — IDOR to Owner Account Takeover via Weak Passwords

hackadvisor

Task: Multi-tenant team collaboration platform with Owner/Admin/Member RBAC; given Member account. Solution: IDOR on /org/{id}/team leaked all user emails and roles cross-org, then guessed Owner password (alex123) to access security settings containing the flag.

$ ls tags/ techniques/
idor_exploitationbroken_access_controlcredential_guessingpassword_pattern_attackdecoy_flag_evasion

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups