Context#
Frameworks map request bodies to ORM entities or document models. If the binder copies every key the client sends, a single PATCH can set role, isAdmin, accountBalance, or ownerId when those keys exist on the model. The signal is a writable sensitive field, not a wrong object id by itself (though you can chain both).
Theory#
Vulnerable code often uses one model or DTO for both low-privilege self-service updates and higher-trust fields on the same table. PUT replace and PATCH merge semantics differ: nested keys can land in deep graph properties a shallow key filter never names.
Practice#
Add privilege keys next to valid fields in a lab#
- Send a small JSON body that is normally allowed (for example,
displayName) plus a second key the UI never shows, such asroleorisAdmin, with a value that should be impossible for the account. Observe response code and a follow-upGETof the same object for field persistence.
Tools#
- curl
- Burp Suite
- Postman