Broken Access Control via API Endpoint Manipulation

dc.date.accessioned2026-07-23T08:18:00Z
dc.date.issued2026-07-21
dc.description.abstractAn authenticated user can bypass access controls by manipulating the API endpoint URL, allowing them to access, modify, or delete sensitive data belonging to another tenant using a valid session token from their own tenant. This report documents the vulnerability, its impact, and recommended remediation.en
dc.identifier.urihttps://dspace.scola.ng/handle/123456789/22
dc.language.isoen
dc.publisherHackerOne Vulnerability Report
dc.rightsAll rights reserved
dc.titleBroken Access Control via API Endpoint Manipulationen
dc.typeTechnical Report

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Access Control Report.pdf
Size:
57.17 KB
Format:
Adobe Portable Document Format