CWE-425
Direct Request ('Forced Browsing')
AI Translation Available
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Status
incomplete
Abstraction
base
Affected Platforms
Web Based
Web Server
Technical Details
AI Translation
Common Consequences
confidentiality
integrity
availability
access control
Impacts
read application data
modify application data
execute unauthorized code or commands
gain privileges or assume identity
Potential Mitigations
Phases:
architecture and design
operation
Descriptions:
•
Consider using MVC based frameworks such as Struts.
•
Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.