Slide 6 of 28
Part 1 · What Is It?Slide 6
Slide 6 · The Outcomes
What happens when function-level auth breaks.
Privilege escalation. Data theft. Platform-wide control.
👑
Privilege Escalation
A regular user calls an admin function to grant themselves admin role, approve their own account, or unlock premium features without authorization.
📊
Mass Data Exposure
Admin reporting endpoints return data on all users — PII, contact details, payment history — without pagination limits or field filtering. One unprotected GET /api/admin/users call exposes everyone.
🗑
Unauthorized Deletion or Modification
DELETE and PUT endpoints restricted to admins let attackers delete other users’ accounts, cancel orders, remove content, or alter records that only admins should touch.
💰
Financial Bypass
Subscription and payment-gated features unlocked for free by calling the underlying API endpoints directly — exactly what Sarda demonstrated with Bumble Boost.
🚫
Platform Integrity Attacks
Moderation functions — ban, approve accounts, remove content — accessible to regular users can be weaponized to mass-ban legitimate users or approve fraudulent accounts at scale.
← Back Who does this? →