The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Privilege Escalation

Srinivashan | Last updated: Feb 10, 2020 01:41PM UTC

Hi, I have done a security testing in Burp Suite, while doing we have faced the below issue for our application. issue description : The application has different level of user access: General user and Admin user. Admin User has access to master module whereas general user is not allowed access to these modules within application. It was possible for normal user to access features allowed only to admin user by manipulating the URL Component. By scanning using Burp suite pro, I have retrieved the above issue but i couldn't reproduce manually using intercepts. Can you help me out in identifying the issue manually?

Michelle, PortSwigger Agent | Last updated: Feb 18, 2020 10:16AM UTC