Broken Object Level Authorization Lab 1

Image

  • There is another bola vulnerabity Contact Mechanic fucntion, try to find it yourself

Image

  • Here is my writeup
  • Firstly open case with contact mechanic and capture it with burp suite then analyze request and response

Image

Image

  • capture report_id request

Image

  • add jwt token to the requets

Image

  • Chnage id value next request and prove bola vulnerability

Image