Secure Legion Labs
OWASP Top 10
Move through a full four-room IDOR progression: simple object reference abuse, multi-parameter ownership bugs, workspace-level leaks, and a deeply nested extreme case.
Single account identifier with direct unauthorized record access.
Cross-customer invoice exposure through mismatched object relationships.
Authorized workspace plus foreign report reference leaking exports.
Tenant, case, and snapshot chaining with a deep object mismatch bug.