Insufficiently Protected Authentication
Reconnaissance
Exploitation
We have a cookie called userId, maybe this application is relying on this cookie for authentication, let's try changing to 2 and sending the request again.
The application did indeed use this cookie for authentication and now we have access to another user's API key.
Last updated