Insecure Direct Object Reference: access resources belonging to other users by manipulating IDs.
api/user/1 to api/user/2“id”:“1” into JSON POST bodies even when not normally present?id=2 or inject into JSON body/resource/1.json vs /resource/1.xml