4 ms·
Yes, it's as simple as the back end not validating that the user id and email address in the requests are tied to the active session. It's a very common mistake
by glyphosate 4y ago
Yes, it's as simple as the back end not validating that the user id and email address in the requests are tied to the active session. It's a very common mistake, often happens when devs try to roll their own session management/access control functionality
- japanman425 4y ago