Bugforge.io CopyPasta Walkthrough

Bugforge.io CopyPasta Walkthrough

Recon

The app exposes a Public Snippets page showing community snippets (JS/Python/CSS/SQL examples).

From UI behavior and intercepts, the app uses a JSON API (Express) and JWT-based auth.

image.png

Key findings

  1. Insecure direct object reference (IDOR) on profile endpoints
  2. Broken password reset / password change authorization

Step-by-step exploitation

1. Enumerate / access an admin profile via IDOR

Intercepting Dashboard requests showed a profile endpoint that returned user data and associated snippets.

Request observed:

  • GET /api/profile/admin

Response included the admin user object and their snippets.

Notable response fields:

This indicated that user profiles were addressable directly by username and were not properly access-controlled.

image.png

2. Bruteforcing Admin login

At this point, bruteforcing the admin account felt like the next logical step.

  • POST /api/login

Result:

  • Username: admin
  • Password: admin123

A successful login returned a JWT token (used as Authorization: Bearer <token>).

image.png

3. Exploit broken authorization in password update

On the Account Settings page, changing a password triggered:

  • PUT /api/profile/password

The request body included both a new password and a user_id parameter:

  • {"password":"testpass","user_id":x}

Because the server accepted the user_id from the client, it allowed updating the password for an arbitrary user (horizontal/vertical privilege escalation), rather than only the currently authenticated user.

The server responded:

  • {"message":"Password updated successfully"}

image.png

image.png

image.png

(Side Note)

Additional testing revealed that obtaining the admin JWT was not required to change a user’s password, this can also be done with a regular user.

image.png

image.png

4. Log in as the target user and retrieve the flag

After updating the password, logging in with the target account succeeded. I proceed with logging in as one of the snippet contributors on the Dashboard (coder123).

image.png

Obtaining The Flag

In the “My Snippets” dashboard, a private snippet titled similarly to bug{...} contained the CTF flag.

image.png

bug{REDACTED}

Root cause analysis

  • Missing authorization checks on profile resources (IDOR).
  • Password-change endpoint trusted client-provided identifiers (user_id) instead of binding the action to the authenticated user.

Remediation

  • Enforce authorization on all user-scoped endpoints (e.g., /api/profile/:username).
  • For password changes, derive the target user strictly from the auth context (JWT/session), not from request parameters.
  • Add server-side role checks for admin-only resources.
  • Log and alert on password change events and suspicious cross-account operations.