Room Link:
https://tryhackme.com/room/idor-aoc2025-zl6MywQid9
Official walkthrough for quick onboarding:
🔗 YouTube Link:
https://youtu.be/geNAA2g-ZnY?si=LOn6plfunNkIichE
Insecure Direct Object Reference
Horizontal

This reveals the request containing user_id.

user_id ParameterChanging the value reveals different parents.
At user_id=15, we discover 10 children.

view_accounts: What is the user_id of the parent with 10 children?15
I solved using MD5 endpoint.

I identified the hash as MD5(11).

Follow the steps:







19
Navigate to:
/parents/vouchers/claim

Perform the attack:

Success:

22643e00-c655-11f0-ac99-026ccdf7d769