User role controlled by request parameter
https://portswigger.net/web-security/learning-paths/server-side-vulnerabilities-apprentice/access-control-apprentice/access-control/lab-user-role-controlled-by-request-parameter
PreviousUnprotected admin functionality with unpredictable URLNextUser ID controlled by request parameter, with unpredictable user IDs
Last updated







