Question: 51
A university’s online learning platform experiences intermit...
A financial services company has developed an API endpoint /api/accounts/{accountId}/transactions that allows users to view their own transaction history. During a security audit, it is discovered that by changing the accountId parameter in the URL, a user can access the transaction histories of other users without any additional authentication or authorization checks.
Which type of vulnerability does this scenario best exemplify?
Share your thoughts, provide feedback, or discuss the question and answer below. You can also help others by answering their questions or providing additional information. Thank you for contributing! 🙏
No comments yet. Be the first to comment!