Client Controlled User Identifier Manipulation
Variants:
Direct Persistent Session
Also Known As:
User Impersonation via Parameter Tampering
Vector Type:
Attack
Relevance:
Generic
Layer:
Application-Level
Platforms:
Any
Target Type:
Application
Affected Mechanisms:
Secure Design
Invented In:
01/02/2000
Added In:
25/12/2014
Quick Introduction to the Topic:
Vector Operation Method:
Attackers can impersonate application users by changing a unique user identifier originating from the client-side. For example - manipulating a user-id, username or email sent to the application in a non-login related scenario