Broken Access Control via API Endpoint Manipulation
| dc.date.accessioned | 2026-07-23T08:18:00Z | |
| dc.date.issued | 2026-07-21 | |
| dc.description.abstract | An authenticated user can bypass access controls by manipulating the API endpoint URL, allowing them to access, modify, or delete sensitive data belonging to another tenant using a valid session token from their own tenant. This report documents the vulnerability, its impact, and recommended remediation. | en |
| dc.identifier.uri | https://dspace.scola.ng/handle/123456789/22 | |
| dc.language.iso | en | |
| dc.publisher | HackerOne Vulnerability Report | |
| dc.rights | All rights reserved | |
| dc.title | Broken Access Control via API Endpoint Manipulation | en |
| dc.type | Technical Report |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Access Control Report.pdf
- Size:
- 57.17 KB
- Format:
- Adobe Portable Document Format