Web Mass Assignment Vulnerabilities
Explanation
class User < ActiveRecord::Base
attr_accessible :username, :email
end{ "user" => { "username" => "hacker", "email" => "hacker@example.com", "admin" => true } }Last updated
class User < ActiveRecord::Base
attr_accessible :username, :email
end{ "user" => { "username" => "hacker", "email" => "hacker@example.com", "admin" => true } }Last updated