1. Web Security Academy
  2. Access control
  3. Lab

Lab: User ID controlled by request parameter


This lab has a horizontal privilege escalation vulnerability on the My Account page.

To solve the lab, obtain the API key for the user carlos and submit it as the solution.

You can access your own account using wiener:peter.

Try Burp Suite for Free

Find access control vulnerabilities using Burp Suite

Try for free