portswigger 5
- IDOR – Password Disclosure via Insecure Direct Object Reference | User ID Controlled by Request Parameter
- IDOR – Unauthorized Access via Predictable Identifier Manipulation | User ID Controlled by Request Parameter
- Broken Access Control – Privilege Escalation via Client-Controlled Cookie | Privilege Escalation via Client-Controlled Cookie
- Broken Access Control – Unprotected Admin Panel via Unpredictable URL Leading to Privilege Escalation | Unprotected Admin Panel
- Broken Access Control – Unprotected Admin Functionality Leading to Privilege Escalation | Unprotected Admin Functionality