1. Challenge Information

2. TL;DR Solution Summary

The endpoint improperly validated JWTs, allowing us to forge a token by modifying the algorithm field to "none", granting admin access.

3. Recon / Initial Analysis

3.1 Files/ Informations Provided

3.2 Service Enumeration (if applicable)

4. Vulnerability Breakdown