BOOK THIS SPACE FOR AD
ARTICLE ADhey guys i’ll explain how to get an easy privilege escalation and get admin privileges
lets start…
first i tried to fuzz subdomains i got a subdomain that is an api
i tried to fuzz dirs with “/seclists/discovery/web-content/raft-large-directories.txt”
i got this endpoint “/register”
i registered and when got in i was having no privileges
i went to profile and changed my name to “admin”
i got all admin privilege and could do any thing that admin can do
i changed the site main image for a POC