Course
In this exercise, the developer fixed the previous bug by preventing direct creation of a user with admin privileges. However, a deeper review reveals another vector to achieve the same result.
Skills covered
Authentication
Authorisation
CWE-285, CWE-697, CWE-1321
Ready to practice?
Get access to this lab and 600+ hands-on exercises with a PRO subscription.