webPromedium

PipeForce

hackadvisor

Task: CRM deal pipeline with role-based access control, Django ORM filtering via query parameters without whitelisting. Solution: Injected _connector=OR parameter to change filter logic from AND to OR, bypassing owner-based access control to read confidential deals.

$ ls tags/ techniques/
access_control_bypassdjango_orm_connector_injectionquery_logic_manipulation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups