🐀
0 pts earned
API Profile
Premium Machine (Locked)
🧩 ExposedAPI
🖧 AD Network — ExposedAPI
🔒 API Users
API Profile
🔒 API Auth
🔒 API Admin
🔒 API Fetch
Mass assignment vulnerability on the profile update endpoint. Adding role=admin to the PUT request body grants admin status, which unlocks an admin panel exposing SSH credentials. Only admin can SSH, so the exploit is mandatory. Root via sudo perl.