3 ms·
This is a problem you see with a model of security where they have security on the front end (meaning the user can only see the bits they should have access to
by vivan 8y ago
This is a problem you see with a model of security where they have security on the front end (meaning the user can only see the bits they should have access to in the UI) but then the back end API is pretty much open to any authenticated user. The idea being that nobody should be able to send API requests if the UI isn't there.
It is a stupid practice.
I "hacked" a student newspaper back when I was at university with a similar "hack". They decided to roll their own CMS rather than using something like Wordpress, because, you know... that makes sense for a small team with little experience.
The user settings page was something like /user/edit/{userid}. I noticed that you can actually change any user's settings (including login) by just changing the userid. So, of course, you just change it to 1 because the first user will inevitably be the admin. This gave control over the whole system.