Sample report, redacted
- Application security assessment
- Client: withheld
- Scope: customer web app and public API
- Testing window: 1 to 12 September 2026
- Issued 15 September 2026
Severity scale
- Info
- Low
- Medium
- High
- Critical
BF-0914-03
Insecure direct object reference on the orders endpoint
- Severity
- HighCVSS 3.1 base score 7.1, vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Status
- Fixed and retested
Summary
Any signed-in customer can read any other customer’s order, including name, phone number and delivery address, by changing the numeric id in the URL. Order ids are sequential, so the whole order history can be enumerated.
Steps to reproduce
- Sign in as a test customer and place an order. Note the order id in the confirmation URL.
- Request the order via the API with the test customer’s token. The response is correct.
- Change the id to the previous number and repeat the request with the same token.
- The response returns another customer’s order with personal data.
Evidence
GET /api/v1/orders/48212 HTTP/1.1
Host: api.redacted.in
Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.redacted
Accept: application/jsonHTTP/1.1 200 OK
Content-Type: application/json
{
"id": 48212,
"customer": {
"id": 10477,
"name": "redacted",
"phone": "+91 redacted"
},
"deliveryAddress": "redacted, Pune 411001",
"items": [{ "sku": "BRK-212", "qty": 1, "price": 2499 }],
"status": "delivered"
}Impact
Personal data of every customer is readable by any other customer. Under the DPDP Act this is a reportable personal data breach. The sequential ids make bulk extraction a one-line script.
Fix
Scope the lookup to the signed-in customer and return 404 when the order is not theirs, so the endpoint does not confirm that an id exists. Add an authorisation test to the API suite so the check cannot regress.
// before
const order = await orders.findById(req.params.id);
if (!order) return res.status(404).end();
return res.json(order);// after
const order = await orders.findOne({
id: req.params.id,
customerId: req.user.id,
});
if (!order) return res.status(404).end();
return res.json(order);Retest
Retested on 18 September 2026. Requests for other customers’ orders now return 404 with an empty body. The authorisation test runs in CI on every pull request. Status: fixed.












