Insecure Direct Object Reference: The Authorization Bug Hiding in Plain Sight
bugbunny.ai | blog | #appsec | #vulnerability-research | #access-control | #web-security | #api-security | #idor | #authorization | #object-level-authorization
Summary
Insecure direct object reference: the app exposes an object ID but never checks ownership, tenant or role—one user reads another's data; fix with centralized object authorization and negative tests.
- Published
- Collected
Skip to content