> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/web/access-control/change-role-in-user-profile.md).

# Rolle im Benutzerprofil ändern

### Die Benutzerrolle kann im Benutzerprofil geändert werden

Dieses Lab enthält ein Administrationspanel unter **/admin**, zugänglich nur für angemeldete Benutzer mit einer **roleid = 2**. / Die Aufgabe besteht darin, unsere eigene Rolle zu ändern, auf die Admin-Oberfläche zuzugreifen und den Benutzer zu löschen **carlos**.

1. Wir verbinden uns mit den angegebenen Zugangsdaten:/ **wiener: peter**
2. Im Profilbereich wird die Änderung der E-Mail-Adresse über eine JSON-Anfrage gesendet, zum Beispiel:

```json
{
"email":"jordan@test.com"
}
```

Die Antwort gibt diese Daten direkt als JSON zurück, was zeigt, dass kein striktes Filtern angewendet wird.

<figure><img src="/files/81cd50666a9dc963b3eb4983c34f5c8b998360b1" alt=""><figcaption></figcaption></figure>

Durch das Einfügen eines zusätzlichen Parameters **roleid**, testen wir:

```json
{
"email":"jordan@test.com",
"roleid": 2
}
```

5. Der Server akzeptiert diese Änderung und gibt ein **302 Found**, was bestätigt, dass unsere Rolle geändert wurde zu **2**.
6. Sobald wir zum Administrator befördert wurden, haben wir Zugriff auf **/admin**, wo wir einfach die Funktion nutzen, um **den Benutzer carlos zu löschen** und damit das Lab zu lösen.

<figure><img src="/files/3f6d85b30719f55d410ee9d80e6772de66514c95" alt="" width="563"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/web/access-control/change-role-in-user-profile.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
