mass-assignment
OfficialExploit API mass assignment flaws.
Software Engineering#authorization#web security#privilege escalation#api security#idor#mass assignment
Authorsecurityfortech
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill helps identify and exploit vulnerabilities in web applications and APIs where user-controlled input can be used to modify sensitive backend data fields that should not be directly accessible.
Core Features & Use Cases
- Detects Mass Assignment: Identifies frameworks and endpoints susceptible to mass assignment.
- Exploits Privilege Escalation: Attempts to gain administrative privileges by injecting
roleorisAdminfields. - Facilitates IDOR: Enables changing ownership of resources by injecting
ownerIdoruserId. - Use Case: An attacker can exploit a profile update endpoint to change their user role to administrator, gaining full control of the application.
Quick Start
Use the mass-assignment skill to test the PUT /api/users/me endpoint for privilege escalation by sending a payload with an admin role.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: mass-assignment Download link: https://github.com/securityfortech/hacking-skills/archive/main.zip#mass-assignment Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.