|
|
|
|
|
by kbenson
3667 days ago
|
|
Yes. Any time you let a non-associated record be displayed by a user session that is not linked to that record and should not have access to it, that's not a problem of easily guessable keys, that's a problem of not securing data by checking access rights. |
|