Access Control 13
- Referer-based access control
- Multi-step process with no access control on one step
- Method-based access control can be circumvented
- URL-based access control can be circumvented
- Insecure direct object references
- User ID controlled by request parameter with password disclosure
- User ID controlled by request parameter with data leakage in redirect
- User ID controlled by request parameter, with unpredictable user IDs
- User ID controlled by request parameter
- User role can be modified in user profile
- User role controlled by request parameter
- Unprotected admin functionality with unpredictable URL
- Unprotected admin functionality