Common Web Vulnerabilities

Broken access control

Many serious vulnerabilities come from assuming that hiding a button or changing a client-side route is sufficient authorization. It is not.

  • Test server-side authorization with separate test identities.
  • Check both horizontal and vertical access boundaries.
  • Verify direct API requests are authorized.
  • Do not access unrelated real users or data.
Lesson complete?Use the next lesson to continue the learning path.