← Reference
Access control

Users can change fields that are not theirs to change

Broken Object Property Level Authorization / Mass assignment

What this means

When saving a form, your app accepts whatever fields arrive. A user can add a field that is not on the screen — a role or a balance — and it will be saved.

Why it matters

This is how an ordinary account becomes an administrator and a free plan becomes a paid one. You cannot spot it in the interface: from the outside it looks like a normal form submission.

When this is not a problem

If the server accepts a strict list of fields, there is no finding.

How to fix it

  • List the fields a user may change explicitly instead of accepting the whole request body.
  • Change privileged fields — role, plan, balance — only through separate actions with their own checks.

Prompt for your AI agent

Only accept the fields a user is actually allowed to change when saving. Never read role, plan or balance from the request body.

Verify the fix: send a privileged field in the request and confirm it was not saved

ClassificationCWE-915CWE-285· API3:2023
Referencesowasp.org
Is your app doing this?
Find out in about a minute — the first scan is free.
Scan your app
Users can change fields that are not theirs to change