Study. uk . com
  1. Home
  2. All questions
  3. Question 349

CompTIA Security+ study material · question 349 of 611

Changing the invoice number in a URL shows another customer's invoice. What is this flaw called?

  1. An insecure direct object reference
  2. Cross-site request forgery
  3. Session fixation
  4. Server-side request forgery
Show the answer

Answer: A. An insecure direct object reference

The application uses a user-supplied identifier to fetch a record without checking the caller is entitled to it.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Broken Access Control

Challenge yourself on this topic → Study as cards