Vulnerability · Access Control
Insecure Direct Object Reference
An access-control flaw where the server accepts a client object identifier and returns the object without verifying the caller is authorised.
See a verified Insecure Direct Object Reference exploit
Pentrova surfaces Insecure Direct Object Reference findings with a replayable PoC artifact and the chain resolver escalates confirmed findings into business impact.