An incident handler investigates a web application breach where an authenticated user modified a hidden form parameter containing an integer account ID, successfully viewing financial records belonging to other customers. Which underlying vulnerability class allowed this unauthorized data access?
The application trusts the client-supplied account ID without verifying that the authenticated user owns that object, so tampering with the hidden parameter returns other customers' records. Authorisation must be enforced server-side against the session identity, not the submitted identifier.
Why this answer
Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input without verifying authorization. Attackers manipulate parameter values to access unauthorized resources, bypassing access controls entirely. Identifying this root cause is critical during incident response to properly scope data exposure, remediate broken access controls across the application architecture, and implement centralized authorization checks.
Exam trap
Candidates often confuse Insecure Direct Object References with Parameter Tampering, missing that parameter tampering is merely the attack mechanism rather than the architectural vulnerability allowing unauthorized access.