Loading HuntDB...

Privilege Escalation: Read-Only to Admin

High
I
Inflection
Submitted None

Team Summary

Official summary from Inflection

While the interface hides the users page from read-only users, they can still perform PUT requests to the API to change their privileges where they only have read-only permissions.

Reported by foobar7

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation