The draft you could change but could not read
An unrelated account couldn't open the draft. Its edits still appeared in the owner's view. The saved contents, not the response code, established the finding.
What happened, what the evidence actually proved, and what a repair needs to get right. Five findings, with the identifying details taken out.
Each note includes HTTP context
and five checks for the proposed repair.
Showing 5 case studies
An unrelated account couldn't open the draft. Its edits still appeared in the owner's view. The saved contents, not the response code, established the finding.
Two anonymous sessions began separately. Then an edit in one appeared in the other. The server had let navigation state choose whose cart to use.
The origin marked account content private. A shared cache delivered it without a session. The login check worked; the delivery policy didn't.
A public form exposed more than a value check. Its helper answered questions about stored data that an anonymous visitor shouldn't have been able to ask.
Required evidence was missing, but the server recorded the case as submitted. Why that result matters, and why it doesn't prove an approval bypass.
Try a broader search or reset the filters above to see all five stories.
Planning an assessment or reviewing a report?
Explore our practical guidesWe test web applications, APIs, and SaaS products, including roles, shared data, and the workflows your customers use. Tell us what you're building and when you need it tested.