IDOR: missing server-side authorisation in an invoice workflow
An authenticated user could modify an invoice identifier and attempt to access another customer's resource. The remediation enforced ownership at the database query layer and was verified with positive and negative authorisation tests.
5 min read