webPromedium

Lab 197 — BillForge — Authorization Bypass via HTTP Parameter Pollution

hackadvisor

Task: Express.js invoicing platform with role-based access control on invoice API endpoint using query parameter id. Solution: HTTP Parameter Pollution — sending duplicate id params (?id=own&id=admin) bypasses authorization (checks first value) while database returns admin's confidential invoice (uses last value).

$ ls tags/ techniques/
http_parameter_pollutionauthorization_desync_via_duplicate_paramsapi_endpoint_discovery_via_js_sourceidor_via_parameter_array_handling

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups