Access control
A regular user can perform admin actions
Broken Function Level Authorization
What this means
Administrative actions — deleting data, exporting user lists, changing settings — work for anyone who knows the address. The button is hidden in the interface, but the request still succeeds.
Why it matters
A hidden button only protects against accidental clicks. Admin addresses are easy to spot in page source, and the damage is irreversible: deleted data and exported lists do not come back.
When this is not a problem
Actions deliberately open to all users are not a finding.
How to fix it
- Check the user's role on the server for every administrative action.
- Treat access as denied by default and open it explicitly.
Prompt for your AI agent
Protect administrative actions with a server-side role check: anything admin-only must return 403 for a regular user.
Verify the fix: call an admin action from a regular account — expect a refusal
Is your app doing this?
Find out in about a minute — the first scan is free.
