Insecure Direct Object References prevalence are quiet common and this risk can be easily exploited. If the attacker is successful then the database passes request to the website and data provided to the attacker. In the system we need to implement validation, if the users manipulates the request, they will not be permitted to unauthorized area of the system. The risk of this risk would be moderate, anyway the impact of risk is moderate. The attacker can change the ID in the URL to fetch different record than the permitted for the user.”]
Source: https://gbhackers.com/a4-insecure-direct-object-references/

