SecurityIntermediate
Insecure Direct Object Reference (IDOR)
Pronunciationin-SIK-yoor di-REKT OB-jekt REF-er-ens
Definition
A security vulnerability where an application exposes a reference to an internal implementation object, such as a database key, allowing attackers to manipulate the input and gain unauthorized access to data.
Where you hear it
- During security code reviews - In penetration testing reports - When discussing authorization bugs
Examples
Changing the user ID in the URL parameter from
101to102allows viewing another user's profile.An API endpoint that returns account details using an unverified record ID is vulnerable to IDOR.
Common mistake
Assuming that hiding the object ID in the user interface or frontend makes the endpoint secure, when the backend still fails to verify authorization.