Lab: User ID controlled by request parameter with data leakage in redirect
This lab contains an access control vulnerability where sensitive information is leaked in the body of a redirect response.
To solve the lab, obtain the API key for the user
carlos and submit it as the solution.
You can log in to your own account using the following credentials:
- Log in using the supplied credentials and access your account page.
- Send the request to Burp Repeater.
Change the "id" parameter to
Observe that although the response is now redirecting you to the home page, it has a body containing the API key belonging to
- Submit the API key.