You have not logged in. Access is limited, Please login to get full Access
Logo

IDOR - L1

Insecure Direct Object Reference (IDOR) is a security vulnerability where an attacker can access or modify unauthorized data by manipulating input values, such as object identifiers in URLs or API requests. This flaw occurs when an application fails to enforce proper authorization checks, allowing direct access to restricted resources. IDOR can lead to data breaches, unauthorized modifications, and privilege escalation, making it a critical issue in web application security.

You are a penetration tester auditing the website craw.in, a new social media platform. You've created an account and are exploring the user profile features. You notice that user profile pages are accessed using URLs like craw.in/profile?id=123.

Answer The Questions

Admin Panel