> For the complete documentation index, see [llms.txt](https://dev-angelist.gitbook.io/writeups-and-walkthroughs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dev-angelist.gitbook.io/writeups-and-walkthroughs/portswigger-web-security-academy/server-side-vulnerabilities/access-control/user-role-controlled-by-request-parameter.md).

# User role controlled by request parameter

https\://portswigger.net/web-security/learning-paths/server-side-vulnerabilities-apprentice/access-control-apprentice/access-control/lab-user-role-controlled-by-request-parameter

#### [Parameter-based access control methods](https://portswigger.net/web-security/learning-paths/server-side-vulnerabilities-apprentice/access-control-apprentice/access-control/parameter-based-access-control-methods)

## Description

This lab has an admin panel at `/admin`, which identifies administrators using a forgeable cookie.

Solve the lab by accessing the admin panel and using it to delete the user `carlos`.

You can log in to your own account using the following credentials: `wiener:peter`

## Solution

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FLBGaiDSDnBY8y49OZVMb%2Fimage.png?alt=media&amp;token=9047a85e-37f8-479d-8301-148eebed1939" alt=""><figcaption></figcaption></figure>

as indicated into description, we know the admin panel path, but without admin credentials we can't do nothing,&#x20;

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FMifmyTFB2Ybs2rvWlAat%2Fimage.png?alt=media&amp;token=5643568f-375f-487e-8bfb-d6a60b8cbb5b" alt=""><figcaption></figcaption></figure>

so we can do normal login with followring credentials: `wiener:peter`

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2Fnr0OE1f2yiawtZuv6zTW%2Fimage.png?alt=media&amp;token=81737ad9-e6c4-4695-bcc5-8530269e38d1" alt=""><figcaption></figcaption></figure>

analysing the http response after login, we can see that there're into cookie and admin flag set to false and the session ID:

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FWssLQSTCoFgOAnD8Lc45%2Fimage.png?alt=media&amp;token=e5ccbeae-13c2-4552-ab02-dcc68af5110c" alt=""><figcaption></figcaption></figure>

Setting the admin flag to 'true' we can do a vertical privilege escalation

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FsVNJBxxtMGxbZIqkwB59%2Fimage.png?alt=media&amp;token=ed2a9562-6ad8-4735-87c2-270b7ce8ea10" alt=""><figcaption></figcaption></figure>

then, go to admin panel and set the flag equals true:

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FhMOdN9mmLwMSO3cTeGai%2Fimage.png?alt=media&amp;token=0e6a5c95-fed5-4722-a0f3-d54e3ce2e903" alt=""><figcaption></figcaption></figure>

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FVv6XtqD5F5nxG54LKZ66%2Fimage.png?alt=media&amp;token=317ed2e5-0fb3-497a-ab51-78aa58cf31ff" alt=""><figcaption></figcaption></figure>

Now, we can finishing deleting user Carlos:

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FLKUtImg5mWgpH5YBlI3g%2Fimage.png?alt=media&amp;token=e095e1be-1db2-457d-8ddd-fef06f5ab614" alt=""><figcaption></figcaption></figure>
