← All Labs
🛡 AUTH BEGINNER +80 XP · +40 no-hint bonus

JWT — None Algorithm Bypass

InvoiceCloud uses JWTs for authentication. The library accepts the algorithm specified in the token header — including 'none'. Forge a token to impersonate the admin.

https://bookshop.local/search