Question 1
Q1During a security assessment of a web application, you discover an API endpoint GET /api/v1/users/{userId}/documents that returns a list of documents for a given user. You observe that you can substitute your userId with that of another user and successfully retrieve their document list. The application correctly validates your authentication token for every request. What is the specific vulnerability category that best describes this issue?
Show answer & explanation
Correct answer: B
This scenario perfectly describes an Insecure Direct Object Reference (IDOR) vulnerability, which is a type of broken access control. The application authenticates the user correctly but fails to authorize them for the specific resource they are requesting. It uses a direct reference to an object (the userId) from user-supplied input without verifying that the authenticated user has permission to access that specific object.