<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>João Paulo Santos Sena</title><description>Notes from the inside of other people&apos;s binaries — security research, reverse engineering, mobile development, and the occasional AI rabbit hole.</description><link>https://notes.forcetower.dev/</link><language>en-us</language><item><title>Privilege Escalation in SAGRES via idPessoa / perfil Parameter Tampering</title><link>https://notes.forcetower.dev/posts/sagres-priv-esc/</link><guid isPermaLink="true">https://notes.forcetower.dev/posts/sagres-priv-esc/</guid><description>A broken-access-control vulnerability in SAGRES (a Brazilian academic-management platform) let any authenticated student act as any other person at the institution by tampering with two query parameters.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>security</category><category>disclosure</category><category>sagres</category></item></channel></rss>