Lab: User ID controlled by request parameter

APPRENTICE

This lab has a horizontal privilege escalation vulnerability on the user account page.

To solve the lab, obtain the API key for the user carlos and submit it as the solution.

You can log in to your own account using the following credentials: wiener:peter

Solution

  1. Log in using the supplied credentials and go to your account page.
  2. Note that the URL contains your username in the "id" parameter.
  3. Send the request to Burp Repeater.
  4. Change the "id" parameter to carlos.
  5. Retrieve and submit the API key for carlos.

Community solutions

Rana Khalil
Michael Sommer (no audio)