CWE-425

Direct Request ('Forced Browsing')

Medium

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Potential Impact

How to Fix

Architecture and Design

Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.

Architecture and Design

Consider using MVC based frameworks such as Struts.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-425 vulnerabilities in your codebase.

Get Security Assessment