Normally a web application should identify a logged in user by data which is stored on the server side in some kind of session storage. Howe...
![[The Burp SessionAuth] Extension for Detection of Possible Privilege escalation vulnerabilities](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMXZG3sHrLKDrTc8UJy0Ts3ZPd-f33ONAsEhUoJTepVsmBMiuv4Scqby_m2YSqXJTynfcIzPg5wrc_gx9tqIELvx6kgLOGiq_VlKBsKeVq-IxUsaNdMc8kWkgdaojW_iNeFzfgUo9vwoM/s72-c/Burp-SessionAuth-ScanIssues.png)
Normally a web application should identify a logged in user by data which is stored on the server side in some kind of session storage. Howe...