Progress

Follow the ordered chain top to bottom. Each step unlocks intel the next one needs; the app enforces those preconditions, so there is no shortcut to impact.

0 / 8 nodes reached this session.

Primary chain

ENTRY - Info disclosure: directory/stats leaks internal ids, emails and account refs
PIVOT A - IDOR/BOLA: read the admin account by its leaked ref (exposes its reset token)
PIVOT B1 - Account takeover: replay the leaked/predictable admin reset token
PIVOT B2 - JWT forge: crack the weak HS256 secret and mint role:admin for the admin uid
IMPACT - Domain owner: reach the role:admin-gated 'transfer domain ownership' action
CHAIN COMPLETE - full path entry -> pivot -> impact achieved

Supporting edges (real, but not sufficient alone)

EDGE - Open redirect in the login 'next' param leaks the session token off-site
EDGE - Front-end bundle leaks config + the hint that the signing key is a weak word