Web Security Academy: Access control — Unprotected admin functionality with unpredictable URL

Beware of those not-so-hidden paths in your app

Deck451
2 min readJan 8, 2024

--

Photo by Jigar Panchal on Unsplash

Hello and welcome to another nice and fun access control lab, provided by Web Security Academy! This lab is all about looking around for clues regarding an administrator panel that has its path disclosed somewhere in the web app.

--

--

Deck451

Senior Software Engineer. Open-source contributor. Knowledge spreader. Fan of everything Python. Cybersecurity enthusiast. TryHackMe top 3%.