Reference

What goes wrong, and what to do about it

Every issue seleth reports has an entry here: what it means in plain language, what it costs when left unfixed, and the change that closes it.

Access control

Anyone can open someone else's record
Your app returns records by their number without checking who owns them. Change one digit in the address and you see another customer's order, profile or document.
Broken Object Level Authorization (BOLA/IDOR)
A regular user can perform admin actions
Administrative actions — deleting data, exporting user lists, changing settings — work for anyone who knows the address. The button is hidden in the interface, but the request still succeeds.
Broken Function Level Authorization
One company's users can see another company's data
Your app serves several companies or workspaces, but database queries are not limited to the user's own workspace. Guess an identifier and a neighbouring company's data opens up.
Cross-tenant data exposure
Users can change fields that are not theirs to change
When saving a form, your app accepts whatever fields arrive. A user can add a field that is not on the screen — a role or a balance — and it will be saved.
Broken Object Property Level Authorization / Mass assignment
Data is available without signing in at all
Some addresses in your app return data to anyone who opens them — no sign-in required. These are usually forgotten internal or temporary pages.
Missing authentication on data endpoint
A password reset link can be used to enter someone else's…
The password recovery link is predictable, never expires, or works more than once. Whoever obtains or guesses it can sign in as that user.
Insecure password reset token handling
Anyone can change someone else's data
Your app checks who is signed in before saving a change, but not whether the record being changed belongs to them. Anyone with an account can edit another customer's order, document or profile by sending the record number.
Broken Object Level Authorization on write

Data storage

Dependencies

Exposure

Your app does not require a secure connection
Your app does not tell browsers to talk to it over a secure connection only. A user's first request can travel in the clear — along with whatever they type.
Missing HTTP Strict Transport Security
Error messages reveal how your app is built
On failure your app shows visitors technical details: server file paths, database queries, library versions.
Verbose error messages
The full user list can be downloaded
Your app lets anyone request every user at once — with no size limit and no check on why they are needed.
Unrestricted enumeration of user records
An internal configuration file is readable by anyone
A configuration file that belongs on the server is served to anyone who
Exposed configuration file
Version control data is published with your app
The hidden folder your version control system uses was deployed together
Exposed version control metadata
Your app is missing recommended browser protections
Browsers offer several protections that only work when your app asks for them: restricting where scripts may load from, refusing to be framed by other sites, and not guessing file types. Your app does not ask.
Missing security headers
Session cookies can be stolen or misused
Your app sets cookies without the flags that keep them safe: they can be read by scripts, sent over an insecure connection, or attached to requests coming from other sites.
Insecure cookie attributes
Any website can read responses from your API
Your app tells browsers that any website may read its responses, and in some cases may do so with the visitor's credentials attached.
Overly permissive cross-origin policy
Browsers refuse to open your app
The security certificate your site presents is not one browsers accept. Visitors see a full-page warning before they see your app, and most of them leave at that point.
Untrusted TLS certificate
Your certificate expires soon
The certificate your site uses runs out shortly. On that day browsers stop opening the app and show a warning instead — there is no grace period.
TLS certificate nearing expiry

External services

Injection

Leaks & secrets

Runtime errors

Search

Server & delivery

Speed

Security reference — seleth