1. Broken Access Control
What is Broken Access Control?
Scenario 1
pstmt.setString(1, request.getParameter("acct"));
ResultSet results = pstmt.executeQuery( ); https://example.com/app/accountInfo?acct=notmyacctScenario 2
https://example.com/app/getappInfo
https://example.com/app/admin_getappInfoReference
Last updated
