Insecure direct object reference
IDOR · An authorisation flaw that arises when an application, on access to a record by address or ID, does not check whether the record really belongs to the user asking for it.
- 01
Why it matters
This is a flaw that automated scanners usually miss but that is very easy to exploit: changing a single number is enough. Invoices, order details, documents and user profiles can be downloaded in bulk this way. The server has to check ownership on every request.
- 02
Example
On a portal, the invoice download address contains a sequential number. A customer who increases the number by one can download another company's invoice; after the fix, the server checks the invoice's owner on every download.
- 03
Common mistake
Thinking the problem is solved by making IDs unguessable. Random IDs only make guessing harder; the real fix is the ownership check on the server.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.