Skip to content

Latest commit

 

History

History
19 lines (11 loc) · 535 Bytes

Multi-step process with no access control on one step.md

File metadata and controls

19 lines (11 loc) · 535 Bytes
  1. Log with admin credentials;
  2. Upgrade or downgrade any user;

  1. Verify the request and notice that you need to confirm;

  1. Send the request from step 3 to repeater;
  2. Log with wiener and copy the session cookie;
  3. Go to repeater and change the session cookie copied from step 5;
  4. Upgrade de wiener user to admin;