Tanuki - 2
Level: Easy Points: 10 Type: Daily Challenge
Lab Interface

In /profile we have option to update or profile

Request to update profile looks like

Key thing to notice here: 1. Email address 2. username passed on request
With this info, the first thing that comes in mind, is possibility to update password of other users. To test this, I created new account.
And then tried to update password of new account by replacinng email and username in update profile request.

Which worked perfectly and gave me flag.
Last updated