Security Notes
search
Ctrlk
  • redhatWhoami
  • Pentestingchevron-right
    • WEP-Penchevron-right
      • Reconnaissance
      • Enumeration
      • OWASP Top 10:2025chevron-right
        • A10 Mishandling of Exceptional Conditionschevron-right
        • A09 Security Logging and Alerting Failureschevron-right
        • A08 Software or Data Integrity Failureschevron-right
        • A07 Authentication Failureschevron-right
        • A06 Insecure Designchevron-right
        • A05 Injectionchevron-right
        • A04 Cryptographic Failureschevron-right
        • A03 Software Supply Chain Failureschevron-right
        • A02 Security Misconfigurationchevron-right
        • A01 Broken Access Controlchevron-right
          • Path Traversal
          • Open Redirect
          • Symlink or Hard Link Following
          • Confused Deputy
          • Incorrect Default Permissions
          • Forced Browsing
          • Server-Side Request Forgery (SSRF)
          • CSRFchevron-right
          • checklistschevron-right
          • mass assignment
      • Checklistschevron-right
    • API-Penchevron-right
    • NET-Penchevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Pentestingchevron-right
  2. WEP-Penchevron-right
  3. OWASP Top 10:2025

A01 Broken Access Control

Path Traversalchevron-rightOpen Redirectchevron-rightSymlink or Hard Link Followingchevron-rightConfused Deputychevron-rightIncorrect Default Permissionschevron-rightForced Browsingchevron-rightServer-Side Request Forgery (SSRF)chevron-rightCSRFchevron-rightchecklistschevron-rightmass assignmentchevron-right
PreviousExposure of Sensitive Information Through Environment Variableschevron-leftNextPath Traversalchevron-right

Last updated 4 days ago