03 Lab: User role controlled by request parameter
Previous01 Lab: Unprotected admin functionalityNext04 Lab User role can be modified in user profile 17efab5460ec808c8da6e67d210bf5a2
Last updated
Last updated
This lab has an admin panel at
/admin
, which identifies administrators using a forgeable cookie.Solve the lab by accessing the admin panel and using it to delete the user
carlos
.You can log in to your own account using the following credentials:
wiener:peter
Exploramos el inicio de sesión
Observamos el parámetro Admin=False
si modificamos esta sección en cada accion que realicemos, tendremos el perfil de Administrador
Eliminamos el usuario, manteniendo el parámetro Admin=False