🔥Some Privilege Escalations + Logic Flaws Led to (DoS, Organization Takeover & more)
Some good privilege escalations, logic bugs that I've discovered at multiple pentest engagements led to critical/high impact findings
0x1 [PrivEsc] Agent Can Send Messages to Admin Private Inboxes





1x1 [PrivEsc] Low Privilege Member Can Take Over Any Team




2x1 [PrivEsc] Custom Role Attacker (Group Manager) Can Remove Owner from Admin Group Leading to Organization Takeover





2x2 [PrivEsc] Attacker with Only Invite Permissions Can Make Himself an Admin




2x3 [Logic Flaw to DoS] Attacker Can Prevent All Users from Inviting New Users by Sending Parallel Requests



3x1 [DoS] Complete API DoS via Uploading a PHP File
This one won't be accepted in bug bounty, but it was the first time I've seen it, so I'll share it with you


PreviousWeb Vulnerable LABsNextExploiting the Authentication Flow to Block Any User from Logging In/Resetting Password + An IDOR
Last updated