Error:
The broken access control vulnerability has not been fixed.
Test
Sign in to SocialJourney using the email "maddieelyse@email.com
" and password "monkey1
".
Submit a post as Maddie Elyse ensuring intercept requests is toggled on, change the api/post/1
in the request header to api/post/2
and verify that the post wasn’t posted as another user.