Identify and exploit Mass Assignment vulnerabilities in APIs. Use this skill when testing REST APIs or application forms that directly map user-supplied JSON or POST input to internal database objects. An attacker can inject undocumented variables (e.g., `is_admin`, `verified`) to illegally modify restricted properties.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge242026年7月11日 更新