Inconsistent security controls
This lab's flawed logic allows arbitrary users to access administrative functionality that should only be available to company employees. To solve the lab, access the admin panel and delete the user carlos
.
Like the previous lab, this one also featured an admin panel, accessible only when logged in as the user "dontwannacryuser," whose email domain is dontwannacry.com.
I proceeded by registering a new user, allowing me to observe that mail updates were possible. All I had to do was provide a new email with the domain @dontwannacry.com (e.g., ichyaboy@dontwannacry.com), granting me access to the admin panel. Consequently, I deleted the user "carlos," successfully resolving the lab.
Last updated