One customer can read another customer’s order
In this model, an authenticated customer gains access to a different customer’s order. In a store, the affected fields and exposed records would determine the confidentiality impact.
- Observed finding
- The test changes the order identifier while keeping the second customer’s identity. The unchecked lookup returns 1 foreign order with status 200.
- Recommended fix
- Protect customer order data. Enforce ownership on every order read and change, derive the actor from the authenticated server context and deny access when the rule cannot be established.
- Verification and follow-up checks
- Repeat the cross-customer request and confirm no order data is returned. Keep positive tests for the owner and negative tests for missing orders and unauthenticated callers in the real API.
Before the fix
Foreign order disclosed: 1; status 200.
After the fix
Foreign order disclosed: 0; status 403.