Application Security216 IDOR via Comma-Injection: How Concatenating Two IDs Leaked Cross-Tenant PII
A multi-tenant document vault enforced a real server-side tenant-ownership check on its permission-grant endpoint - and it was still bypassable. The authorization…















