Skip to main content

IDOR (Insecure Direct Object Reference)

A web vulnerability where an application exposes internal object references (like database IDs) in URLs or parameters, allowing attackers to access unauthorized resources by modifying the reference.

vulnerability web
Practice Challenges 1 category
Related Labs 1 lab
View all labs →
Active CTF Events 3
View all events →
Related Terms 12

Ready to learn IDOR hands-on?

Put theory into practice with real hacking labs, CTF challenges, and guided courses on Parrot CTFs Events.

Get Started Free