issues
search
aerdnaaa
/
Application-Security-Project
0
stars
0
forks
source link
API -Broken Object Level Authorization (vuln)
#1
Open
aerdnaaa
opened
4 years ago
aerdnaaa
commented
4 years ago
[x] Allow user to view a coupon where only people who have spent a lot of money can access
[ ] Allow all user to view/edit all of the other users information (maybe not)
[ ] Allow admin to edit, delete products