CASP+ CAS-003 – Question 135


An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to:
Which of the following is the MOST likely vulnerability in this ERP platform?

A. Brute forcing of account credentials
B. Plan-text credentials transmitted over the Internet
C. Insecure direct object reference
D. SQL injection of ERP back end

Correct Answer: C