authorization 9
- Authentication Bypass – Direct Dashboard Access | Pivot HR
- Privilege Escalation – Client-Side Role Cookie Tampering | Session Swap
- IDOR – Account Export Data Disclosure | Remittance
- Workflow Access Control Bypass – Admin Privilege Escalation | Lazy Human Resources
- GraphQL BOLA via Introspection & Insecure Resolver Access | Slate Quarry
- Command Injection & Broken Function Level Authorization | NewsForge
- IDOR in Order Access – Unauthorized Order Data Exposure | Hartwood
- UUID-Based IDOR Through Member API | Apex
- IDOR – Unauthorized Access to Borrower Records | Overdue