- Broken Object Level Authorization (BOLA) --> Like IDOR (resource level)
- Broken User Authentication --> Tokens
- Excessive Data Exposure --> Information Disclosure
- Lack of Resources & Rate Limiting
- Broken Function Level Authorization (BFLA) --> Like IDOR (functionality level)
- Mass Assignment --> Being able to change more than what is allowed or being able to add an extra parameter in the request which will get processed.
- Security Misconfiguration --> XSS from CORS
- Injection --> Try NoSQLi
- Improper Assets Management --> Like keeping v1 around when v6 is available
- Insufficient Logging & Monitoring
api
Directory actions
More options
Directory actions
More options
api
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|
parent directory.. | ||||