Stumbled upon the wildest privilege escalation bug ever! 🐛
-Create a custom role, with Role create/update permission, Save.
- Right after, delete all permissions from the role.
- Assign the role to attacker.
- Attacker can become `admin`, from ui! 😆
#BugBounty#CyberSecurity
Excited to share that I've crossed 1500 reputation on HackerOne! Grateful for the learning and the opportunities to contribute to security. #CyberSecurity#BugBounty#hackerone
Tag a hacker that you're grateful to, and always look up to in your journey..
We're all humans after all, show some recognition to those you love! ❤️🩹
I'll start..