Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
添加漏洞“IDOR”
不安全的直接对象引用 (Insecure Direct Object References, IDOR) 是一种常见的 Web 应用程序漏洞,其允许攻击者访问应该被限制的资源或信息。下面是一些 IDOR 漏洞的例子:
一个在线商店的 URL 包含了商品的编号,攻击者可以通过操纵这个编号来访问限制访问的商品。
一个网站的 URL 包含了用户的用户名,攻击者可以通过操纵这个用户名来访问其他用户的信息。
一个应用程序的 URL 包含了文件的编号,攻击者可以通过操纵这个