
Challenge 10/36: Mass Assignment to Admin Role - OopsSec Store CTF
ctfcybersecuritymass-assignmentprivilege-escalationinput-validationweb-securityvulnerabilitychallengeoopssec-store
Challenge 10/36 · Trusting the Client. Mass assignment to admin role. Medium difficulty · Input Validation · 45–60 min. Exploiting a mass assignment vulnerability in OopsSec Store's signup endpoint to create an account with administrator privileges. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap at https://koadt.github.io/oss-oopssec-store/roadmap#challenge-10. Walkthrough available at https://koadt.github.io/oss-oopssec-store/posts/mass-assignment-admin-privilege-escalation (spoilers, read it once you are stuck). Star OopsSec Store on GitHub at https://github.com/kOaDT/oss-oopssec-store