⚠ Sandboxed environment — This is an intentionally vulnerable application running inside an isolated Docker container with fake data. Nothing you do here can harm the host machine or other users.

A01 – Broken Access Control

OWASP A01:2025 CWE-22 CWE-200 CWE-548 CWE-639

Four different ways access control can fail. Each tab below isolates one CWE so you can focus on it. All four share the same root cause: the server trusts a user-supplied value to decide what data to return.

CWE-22 Path Traversal CWE-200 IDOR CWE-548 Directory Listing CWE-639 Privilege Key
CWE-200 Information Exposure (IDOR)

"IDOR" — Insecure Direct Object Reference. The server returns an order by id but never checks whether the id belongs to the caller.

Vulnerable code:
oid = int(request.args['id'])
return jsonify(ORDERS[oid])   # no ownership check

Try it yourself

Your own order

Submit 1 — you are alice, this is fine.

Read someone else's

Submit 2 or 3. The server returns bob's or admin's order, credit card and all.