Pasindu's Blog

Home

❯

PortSwigger Labs

❯

Access Control Vulnerabilities

Access Control Vulnerabilities

Jun 22, 20261 min read

Access Control Vulnerability - PortSwigger Practice Lab



13 items under this folder.

  • Jun 22, 2026

    Insecure direct object references

    • PortSwigger
  • Jun 22, 2026

    Method-based access control can be circumvented

    • PortSwigger
  • Jun 22, 2026

    Multi-step process with no access control on one step

    • PortSwigger
  • Jun 22, 2026

    Referer-based access control

    • PortSwigger
  • Jun 22, 2026

    URL-based access control can be circumvented

    • PortSwigger
  • Jun 22, 2026

    Unprotected admin functionality with unpredictable URL

    • PortSwigger
  • Jun 22, 2026

    Unprotected admin functionality

    • PortSwigger
  • Jun 22, 2026

    User ID controlled by request parameter with data leakage in redirect

    • PortSwigger
  • Jun 22, 2026

    User ID controlled by request parameter with password disclosure

    • PortSwigger
  • Jun 22, 2026

    User ID controlled by request parameter, with unpredictable user IDs

    • PortSwigger
  • Jun 22, 2026

    User ID controlled by request parameter

    • PortSwigger
  • Jun 22, 2026

    User role can be modified in user profile

    • PortSwigger
  • Jun 22, 2026

    User role controlled by request parameter

    • PortSwigger

Created with Quartz v4.5.2 © 2026

  • GitHub
  • Discord Community