{ LOGIN:"api/auth/login" GET_USER:"api/v2/user/dashboard" SIGNUP:"api/auth/signup" RESET_PASSWORD:"api/v2/user/reset-password" FORGOT_PASSWORD:"api/auth/forget-password" VERIFY_OTP:"api/auth/v3/check-otp" LOGIN_TOKEN:"api/auth/v4.0/user/login-with-token" ADD_VEHICLE:"api/v2/vehicle/add_vehicle" GET_VEHICLES:"api/v2/vehicle/vehicles" RESEND_MAIL:"api/v2/vehicle/resend_email" CHANGE_EMAIL:"api/v2/user/change-email" VERIFY_TOKEN:"api/v2/user/verify-email-token" UPLOAD_PROFILE_PIC:"api/v2/user/pictures" UPLOAD_VIDEO:"api/v2/user/videos" CHANGE_VIDEO_NAME:"api/v2/user/videos/<videoId>" REFRESH_LOCATION:"api/v2/vehicle/<carId>/location" CONVERT_VIDEO:"api/v2/user/videos/convert_video" CONTACT_MECHANIC:"api/merchant/contact_mechanic" RECEIVE_REPORT:"api/mechanic/receive_report" GET_MECHANICS:"api/mechanic" GET_PRODUCTS:"api/shop/products" GET_SERVICES:"api/mechanic/service_requests" BUY_PRODUCT:"api/shop/orders" GET_ORDERS:"api/shop/orders/all" GET_ORDER_BY_ID:"api/shop/orders/<orderId>" RETURN_ORDER:"api/shop/orders/return_order" APPLY_COUPON:"api/shop/apply_coupon" ADD_NEW_POST:"api/v2/community/posts" GET_POSTS:"api/v2/community/posts/recent" GET_POST_BY_ID:"api/v2/community/posts/<postId>" ADD_COMMENT:"api/v2/community/posts/<postId>/comment" VALIDATE_COUPON:"api/v2/coupon/validate-coupon" } Authorization: Bearer eyJhbGciOiJSUzI1NiJ9eyJzdWIiOiJwaXBpQGdtYWlsLmNvbSIsInJvbGUiOiJhZG1pbiIsImlhdCI6MTY5NDExMDkwNSwiZXhwIjoxNjk0NzE1NzA1fQ==.AILAp2S1DjGdNiN4NxFki6owXhsnBapnFaeI6yAszrRiIv5UOQASuu8Bc7AVLwsbzp8aE24100UHBoLlGbeJUEUZFMORqc5HV5exKE3oCIIJoxSj6T25LqjbwlFUT4xtJgmU7EkVKnSMP5y2GayonTwhjFIjd7VCJZL8GUlv_aQ3EwDvBqALHLbN234nOZfezPG_BkOmsdcSWaaQqwJZhiLBOdZ6h5I8nCjLid3mb6p2PxRDpq_sb3kWZRJ5I_2mRbbh44dK4-qAk2Amt28JWVjKtEwaeqiHi6_gUowYEr2ZfEB9Qbi_RQAsyDu3r2sMgNvmN45xqh8DMSFCU3Lklg Insecure Configuration & Data Exposure: PATH: /community/api/v2/community/posts/recent (localhost:8888/forum/) {"id":"hS8TrbqU85azZV3mXvqXPo","title":"gg","content":"GG","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T17:14:42.83025998Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T17:14:42.830263891Z"} {"id":"7s8ZfpGDmD5KNhUNq8RV7P","title":"asdfasdfasdfasdfasdfasdfasdfasdfasdf","content":"asdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasfasdfasdfasdf","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:41:28.698816193Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:41:28.698819895Z"} {"id":"FScKiYUGGbueCiqh5NuAmh","title":"a","content":"a","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:41:56.030567365Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:41:56.030570787Z"} {"id":"fQS8X9B4hmPtdeTo9hcj2Y","title":"Hello","content":"How are you doing guys?","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:42:19.100412868Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:42:19.100416639Z"} {"id":"egKJBrnKePPDnu5VivxLnC","title":"Hello","content":"hello. My name is Hello.\nIt is my new post. I\u0026amp;#39;m just learning how to use your site. I like it already.","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:43:04.911158138Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:43:04.911161421Z"} {"userReducer":"{\"fetchingData\":false,\"isLoggedIn\":true,\"accessToken\":\"eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJwaXBpQGdtYWlsLmNvbSIsInJvbGUiOiJ1c2VyIiwiaWF0IjoxNjk0MTEwOTA1LCJleHAiOjE2OTQ3MTU3MDV9.AILAp2S1DjGdNiN4NxFki6owXhsnBapnFaeI6yAszrRiIv5UOQASuu8Bc7AVLwsbzp8aE24100UHBoLlGbeJUEUZFMORqc5HV5exKE3oCIIJoxSj6T25LqjbwlFUT4xtJgmU7EkVKnSMP5y2GayonTwhjFIjd7VCJZL8GUlv_aQ3EwDvBqALHLbN234nOZfezPG_BkOmsdcSWaaQqwJZhiLBOdZ6h5I8nCjLid3mb6p2PxRDpq_sb3kWZRJ5I_2mRbbh44dK4-qAk2Amt28JWVjKtEwaeqiHi6_gUowYEr2ZfEB9Qbi_RQAsyDu3r2sMgNvmN45xqh8DMSFCU3Lklg\",\"id\":11,\"name\":\"titi\",\"email\":\"pipi@gmail.com\",\"number\":\"29283929\",\"role\":\"ROLE_USER\",\"userData\":{\"available_credit\":90}}","profileReducer":"{\"videoId\":0,\"videoData\":null,\"videoName\":null,\"profilePicData\":null}","_persist":"{\"version\":-1,\"rehydrated\":true}"} Password1! emails: hello@gmail.com a@a.com email@email.com pipi@gmail.com asdfasdf#zsa@asfaef.com test@example.com admin@example.com UserA@email.com admin@admin.com admin@gmail.com admin2@admin.com admin3@admin.com adam007@example.com persist:reducers {"userReducer":"{\"fetchingData\":false,\"isLoggedIn\":true,\"accessToken\":\"eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJhZGFtMDA3QGV4YW1wbGUuY29tIiwicm9sZSI6InByZWRlZmluZWQiLCJpYXQiOjE2OTQ4NjQ5MjIsImV4cCI6MTY5NTQ2OTcyMn0.V2ZsrFgb_rIOBkR0KCodPUyI-YdkShRXsUCLdLKI5RDVpM9vRC3B7lYaJ52m8iz3VerIh0gz-wHo_EOR45U05kaJyGcQit12OJmvsLcZZmH5GrXdrUThWNb2TeScH3jX_sgvi-bFlCnVHxNeCiNPNOuiXLtVO-BoKEUKLzoc2TL830MaRakRubbxuJq3M_7sOGrgmUH7JbMmpAeErKiQiNHT9J-gFv4SDjVHO6yqXqEsJNkaGZgeY5nRT9vT0OnheJsdm7xPn3JUom7raA52T6MBlAinXawcSnO0_jPOCAZ4Iu5c_644Wc2tuEiceyh5EZ7Y7ULSPzDQPUqhCjMajg\",\"id\":1,\"name\":\"Adam\",\"email\":\"adam007@example.com\",\"number\":\"9876895423\",\"role\":\"ROLE_PREDEFINE\"}","profileReducer":"{}","_persist":"{\"version\":-1,\"rehydrated\":true}"} Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJhZGFtMDA3QGV4YW1wbGUuY29tIiwicm9sZSI6InByZWRlZmluZWQiLCJpYXQiOjE2OTQ4NjUxOTIsImV4cCI6MTY5NTQ2OTk5Mn0.jKlZ_ode4p4wCyVtVtYgYbCxDf_UZnNFoU7pF23T9-FiffrRHbaGvqPL5AynMDrT4EDVpO-L_ISQSCfi1GipooiCNZ4qjbdLUbkJQUIHhx2Yf_jGtN5kKA4tWwAhXcP5ITlzghELs9uv_QJQoTr_J7fqkAnb2UVHkCORtthHMdeu4mNj03XdY4a6P9JBlzNUFpTzUk0DRT7LzLh7J8BX12ji5-rjR8RY0a4ybxrJ3fj2a3GW4n1y-bA6VdDd1G8ZqAyYlWt4e1BiW-gCwMs53ftlwhK9xxxBzIu0hSIeI3Mqzi6kjoBb2sxIfmMr2rUfEb4ug8jq0MI8zmNDhE04XA jhon@example.com Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJqaG9uQGV4YW1wbGUuY29tIiwicm9sZSI6Im1lY2hhbmljIiwiaWF0IjoxNjk0ODY0NTA0LCJleHAiOjE2OTU0NjkzMDR9.BS4ge4Z8H7zkx127f551LsFSInUBw1herN2JkPY0KK_DlbMYW9SbegP6v4uri8jChSnC6oXbqN7wMb7Xe6KHfunyLXsezbdlJWlipZqekPFIBVQV0wUbmj_Qg2LjSvpI6dC-HeUCMjJMAZQx2X7tTQUvUTIFradoGdU_S00yzis6s7L9dTBzPr2tgaBgeH_rVW5zuihEC0ROiwisTEj1oPTLkdPzNTSJzBWECJdf5WQGZ__e6m9tXSYU8ySK_RWS6z4iP071mRDTdf_RAdVAydiD9WBK4iy9s6Jss8-pLYmazQlkI2tOwrFsYkvm_Or1MtHP_SGEKIq-kPn9bCLe_g jhon - mechanic - vehicle's vin disclosure at workshop/api/mechanic/mechanic_report?report_id=8 with the jhon's authorization token. f02fd7c8-425f-4856-9fc0-d4cf0f4a456d Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJVc2VyQUBlbWFpbC5jb20iLCJyb2xlIjoidXNlciIsImlhdCI6MTY5NDg1Mzk2NSwiZXhwIjoxNjk1NDU4NzY1fQ.a3wdv41DxdYkGlh-wqcz5uujWjsX9UhEdqQr2XB4sXVzMRpYNLStWYfI2LExIRRDiVEAq91lqRSRyGHndVbkHtN-eHSDfHVpom7th6tv5dC_fTe_rn5QJU3sSDgioNDvly_LgDSFkZWjY589Y79jw9GVSmEG-DkgG7j-8OKjzr3Z1i64Uu4LiFjxklrPNlQOKcLgY2R-4vOLTUoTlbOOdKzVIz_0GGVcXJYT7o4RsZkOk00KSRXGv83_EHbktC6qSD1-Cl-3MsmQgQBtBeRQYgvalj0-Txmmea9JyZ2Z96GdO02ilE8eLUjnncH2aPX3PcoZMJdMuVkT2pYlpvI_Dw UserB@email.com de2efd6c-ef46-4342-b4c1-03909155b736 Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJVc2VyQkBlbWFpbC5jb20iLCJyb2xlIjoidXNlciIsImlhdCI6MTY5NDg1NDA3MCwiZXhwIjoxNjk1NDU4ODcwfQ.M62B4QZjgVheSC_MDXSt4tqu1YLIZSXWdUmSv-xPQpSjif24Btd-JEAvs693xtFhlWASUbrcO6NtqZiFFMEeJF-y57YjbBcKA7MGcfv7X2ow_X8UeSh6wRBafZlZ5b3ZojdwTb5NlS4aPN8duk4-fuWxO6BggwJe6fJOG362tNDxviYMkUQ1y5rMCBz5aG2cmepVWcjASIw1p1k7I44Kyu3lEdQsrrEhM8-c8UyIb6ZQdpUHS8HVUp7YQzrCtkLMIRhPJ99NVcNtTX6eeY_ESYO652jymwbP5haHb41VdEAqb_EZ9cfm5xnjBBErHplizFDh61Rz6XKA6bgtLMJ61w { "keys": [ { "kty": "RSA", "e": "AQAB", "use": "sig", "kid": "MKMZkDenUfuDF2byYowDj7tW5Ox6XG4Y1THTEGScRg8", "alg": "RS256", "n": "sZKrGYja9S7BkO-waOcupoGY6BQjixJkg1Uitt278NbiCSnBRw5_cmfuWFFFPgRxabBZBJwJAujnQrlgTLXnRRItM9SRO884cEXn-s4Uc8qwk6pev63qb8no6aCVY0dFpthEGtOP-3KIJ2kx2i5HNzm8d7fG3ZswZrttDVbSSTy8UjPTOr4xVw1Yyh_GzGK9i_RYBWHftDsVfKrHcgGn1F_T6W0cgcnh4KFmbyOQ7dUy8Uc6Gu8JHeHJVt2vGcn50EDtUy2YN-UnZPjCSC7vYOfd5teUR_Bf4jg8GN6UnLbr_Et8HUnz9RFBLkPIf0NiY6iRjp9ooSDkml2OGql3ww" } ] } http://localhost:8888/workshop/admin/login/?next=/workshop/admin/ http://localhost:8888/workshop/admin