Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Insecure Direct Object Reference: The Authorization Bug Hiding in Plain Sight

Summary

Insecure direct object reference: the app exposes an object ID but never checks ownership, tenant or role—one user reads another's data; fix with centralized object authorization and negative tests.
Published
Collected

original ↗