4. of Spoofing
An attacker can anonymously connect because we expect authentication to be done at a higher level.
Threat |
|
Addressing pages directly that you would normally reach via a login flow. If you know the address and the login was in the flow, it may be possible to bypass, thereby indicating a missing object-level access control. |
|
CAPEC |
CAPEC-87 - Forceful Browsing |
ASVS |
4.2.1 - Ensure object level access control is implemented correctly and authorizations are performed on every request |
CWE |
CWE-425 - Direct Request (‘Forced Browsing’) |
Mitigations |
|
|