$ cat writeup.md…
$ cat writeup.md…
bug-makers
Task: Node.js/Express password manager with JWT auth, admin bot (Puppeteer), and CSRF protection. Vulnerability is client-side parameter pollution where duplicate query params are parsed differently by server (parseInt on array) vs client (last value from getAll). Solution: craft URL with two id params — first passes server auth, second causes client-side fetch to traverse path to /admin/addAdmin, promoting attacker's user to admin via the bot's session.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar