API6:2023: Unrestricted Access to Sensitive Business Flows
Business flows (purchase, ticket-buying, comment-posting) that can be abused at scale by automation despite individual requests being authorized.
How it's found
Found by reviewing business-critical flows (purchase, signup, invite) for missing anti-automation controls such as rate limiting or challenge steps.
Standards mapping
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is API6:2023 Unrestricted Access to Sensitive Business Flows?
Business flows (purchase, ticket-buying, comment-posting) that can be abused at scale by automation despite individual requests being authorized.
How do you find Unrestricted Access to Sensitive Business Flows?
Found by reviewing business-critical flows (purchase, signup, invite) for missing anti-automation controls such as rate limiting or challenge steps.
Which CWEs map to API6:2023?
API6:2023 maps to CWE-799, CWE-840.
Does TurboPentest test for Unrestricted Access to Sensitive Business Flows?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related OWASP categories
- OWASP API Security Top 10API1:2023: Broken Object Level Authorization
- OWASP API Security Top 10API2:2023: Broken Authentication
- OWASP API Security Top 10API3:2023: Broken Object Property Level Authorization
- OWASP API Security Top 10API4:2023: Unrestricted Resource Consumption
- OWASP API Security Top 10API5:2023: Broken Function Level Authorization
- OWASP API Security Top 10API7:2023: Server Side Request Forgery (SSRF)
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest