Order API returns other customers’ invoices when the ID is changed
- Severity
- High
- Where
- /api/orders/:id/invoice
- Class
- Broken access control
- Status
- Retested
Any signed-in customer can read any other customer’s invoices - names, delivery addresses and order totals - by changing one number in a request. No special tools needed.
In plain words, so it can be ranked without a call.
Easy to find, needs only an ordinary account, and exposes personal data for every customer who has ever ordered.
The reasoning is written down, so you can argue with it.
- 1. Sign in as test customer A.
- 2. GET /api/orders/10482/invoice 200, A’s invoice
- 3. GET /api/orders/10481/invoice 200, B’s invoice
Exact requests, so a developer sees it for themselves in minutes.
Check the order belongs to the signed-in user before returning it. The same check was missing on the receipt and shipping-label routes; both are in the same pull request.
The change itself, in your code - not a link to a checklist.
The request from step 3 now returns 403 for every order the caller does not own, on all three routes. Customer A’s own invoice still loads.
Closed only after we have tried again.