Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it's as simple as the back end not validating that the user id and email address in the requests are tied to the active session. It's a very common mistake, often happens when devs try to roll their own session management/access control functionality




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: