idor 14
- IDOR in Password Reset API Leads to Administrator Account Takeover | TheForms
- Password Change IDOR Leads to Administrator Account Takeover | Noted
- IDOR – Unauthorized Grant Approval via Workflow Manipulation | Briarcliff Foundation
- IDOR – Account Export Data Disclosure | Remittance
- IDOR via WebSocket Subscription – Cross-Order Data Exposure | JoyStick
- GraphQL BOLA via Introspection & Insecure Resolver Access | Slate Quarry
- Command Injection & Broken Function Level Authorization | NewsForge
- IDOR via Sequential Order IDs | Cheesy Does It
- IDOR in Order Access – Unauthorized Order Data Exposure | Hartwood
- UUID-Based IDOR Through Member API | Apex
- IDOR – Unauthorized Access to Borrower Records | Overdue
- IDOR – Unauthorized Access to Shared Notes via Base64 ID Manipulation | BugForge
- IDOR – Password Disclosure via Insecure Direct Object Reference | User ID Controlled by Request Parameter
- IDOR – Unauthorized Access via Predictable Identifier Manipulation | User ID Controlled by Request Parameter