Ace of Elevation of Privilege
You’ve invented a new Elevation of Privilege attack.
Threat |
|
You have both an admin interface and a user interface to your web application and on login, you redirect the users to the relevant area of your site. However, you have not implemented object-level access control, so, if a user knows the URL of an administration page, the system will let them access it. |
|
CAPEC |
CAPEC-1 – Accessing functionality not properly constrained by ACLs CAPEC-180 – Exploiting incorrectly configured access control security levels |
ASVS |
4.2.1 – Ensure authorization is performed on all objects |
CWE |
CWE-425 – Direct request (forced browsing) |