Learn Web Application Security
An introduction to the most common web vulnerabilities: how they're exploited, and how they're fixed.
Explains any vulnerability in plain language, then generates practice questions for your level.
Why is changing the invoice ID in the URL a vulnerability?
The server checks you're signed in, but not that the invoice is yours. That's broken object-level authorization: BOLA.
Quick check. Which fix stops it?A. Hide the ID in the pageB. Look it up by ID and owner
B
Right. Hiding the ID doesn't help: an attacker never needed your page.
Illustrative example. Feature in development.