Access Control
Medium · IDOR

The UUID Wasn't Secret

SecureLearn replaced sequential profile IDs with UUIDs and assumes that makes records impossible to discover. Your own profile uses a UUID, but another feature exposes UUID references for students. Determine whether possession of a leaked UUID is enough to cross the authorization boundary.

Objective

Find another student's UUID through a separate application feature, reuse it on the profile route, and recover the flag.

Target

SecureLearn

Usernamestudent1
Passwordstudent123
Launch target

Submit flag