lab 7
- Insecure deserialization - Theory
- Insecure deserialization - Practice
- Authentication - Password reset broken logic
- Access control - UID controlled by request parameter
- Access control - UID controlled by request parameter with data leakage in redirect
- Access control - Insecure Direct Object References
- PS Access control lab - User role can be modified in user profile