Broken Access Control via API Endpoint Manipulation

Loading...
Thumbnail Image

Authors

Journal Title

Journal ISSN

Volume Title

Publisher

HackerOne Vulnerability Report

DOI

Abstract

An authenticated user can bypass access controls by manipulating the API endpoint URL, allowing them to access, modify, or delete sensitive data belonging to another tenant using a valid session token from their own tenant. This report documents the vulnerability, its impact, and recommended remediation.

Description

Keywords

Citation

Endorsement

Review

Supplemented By

Referenced By

Rights and licensing

All rights reserved