|
|
|
|
|
by pixel8account
935 days ago
|
|
It's good to consider this but... Plenty of sites expose user ID as a regular integer. In some cases you might want to avoid this (leaking user count to competitors etc), but I have never heard about anyone calling this a vulnerability. |
|
https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Dire...
When I first joined $company, HR sent me a SharePoint document with a numerical ID. Incrementing or decrementing the ID allowed me to view personal information of other employees including their pay.