Broken Access Control via API Endpoint Manipulation
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
HackerOne Vulnerability Report
DOI
Abstract
An authenticated user can bypass access controls by manipulating the API endpoint URL, allowing them to access, modify, or delete sensitive data belonging to another tenant using a valid session token from their own tenant. This report documents the vulnerability, its impact, and recommended remediation.
Description
Keywords
Citation
Collections
Endorsement
Review
Supplemented By
Referenced By
Rights and licensing
All rights reserved