Summary
A normal user has permission to create/update users, they can become admin by editing the isadmin value in the request
PoC
Change the value of the isadmin field in the request to true:
https://drive.google.com/file/d/1e8XJbIFIDXaFiL-dqn0a0b6u7o3CwqSG/preview
Impact
Elevate user privileges