Nov. 16, 2023, 2:54 p.m. | /u/Different_Fun_4066


I solved several labs on portswigger, in which I was given admin credentials to explore admin actions and then leverage access control vulnerabilities to do admin actions while logged in as normal user. Question is, how would we typically be able to find ways to perform such actions in real world scenario, as we would not have access to admin account to explore those actions?

For reference, lab which provides admin account:

