← All Challenges
Challenge 47 of 66
Mass Assigner
🟠 Hard
Web App
+100 XP
The user profile update API accepts any field. Add "role":"admin" to your update request to escalate privileges.
Send extra fields in the JSON body that the API does not expect but still processes.