3 Simple broken access control vulnerabilities you should hunt for, while logic vulnerabilities testing #BugBounty #bugbountytip #bugbountytips #Bugcrowd
If the website allows creating an organisation you have ex.
2 roles admin && admin
access the user's information endpoint with the admin 2 , save the request
With the previous admin downgrade his role to few user and execute the request and see If you can access the users PII