nerdexam
CompTIA

CAS-003 · Question #350

An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to: Which of the following is the MOST likely vulnerability in this ERP platform?

The correct answer is C. Insecure direct object reference. https://portswigger.net/web-security/access-control/idor

Technical Integration of Enterprise Security

Question

An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to:

Which of the following is the MOST likely vulnerability in this ERP platform?

Options

  • ABrute forcing of account credentials
  • BPlan-text credentials transmitted over the Internet
  • CInsecure direct object reference
  • DSQL injection of ERP back end

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    94% (60)
  • D
    2% (1)

Explanation

https://portswigger.net/web-security/access-control/idor

Topics

#insecure direct object reference#IDOR#web application security#ERP security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice