Curious captives

Insufficient workflow validation


Listen Later

This application makes a flawed assumption about the user's privilege level based on their input. As a result, it is possible to exploit the logic of its account management features to gain access to arbitrary users' accounts.

Writeup of this lab: webapp.tymyrddin.dev/docs/business/8.html
Education backed by ut7.fr/

...more
View all episodesView all episodes
Download on the App Store

Curious captivesBy