Access-control bugs & the OWASP lens

P57.vuln-classes.02 · Audience: guest, it-ml, language-pro · Prerequisites: Injection & the untrusted-input lens

Real LLM grading for this pageLLM grading (this page):

Broken access control is consistently the most common serious finding in real applications — and it is the P56 models mis-applied. This module fixes the two classic shapes: IDOR (fetching an object by id without checking the caller owns it) and mass assignment (splatting a request body onto a record). It closes on the OWASP Top 10 as a map, not a checklist.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — fix broken access control (IDOR)

Loading exercise…

Rung 2 — stop mass assignment with an allowlist

Loading exercise…

Interview rung — the OWASP lens (free-form)

Loading exercise…

My notes on this module

Loading your notes...

Access-control bugs & the OWASP lens — TransformerLab