HACKR.GG
LabsOAuth Login
OAuth AttacksHard

OAuth Login

Critbook's OAuth flow doesn't validate the state parameter. Hijack the authorisation code and log in as another user.

// Machine control
Checking session...
// Submit flag