Description:

The Request Management App is used to view all pending requests for each user. It’s a pretty basic website, though I heard they were working on something new.

Anyway, did you know that one of the disgruntled employees shared some company secrets on the Requests Management App, but it's status was set denied before I could see it. Please find out what it was and spill the tea

Challenge Analysis

Well Starting right away looking at the site given , One would directly be brought up with a table as such Containing 3 major things

image.png

Since this was a sourceless challenge , we do the normal analysis that one would ie go through whatever client-side js one could get in hand

Majorly what we happen to have in hand is well

Straight off the back when we are to view _buildManifest.js you are shown a few routes as such

    sortedPages: ["/", "/_app", "/_error", "/v2-testing"]

There also exists a /api/list Which was easily discovered by just looking at the requests which the page was calling

image.png