Description
Binding a request body directly to a domain object and saving it can allow attackers to overwrite internal fields such as administrator status, balances, or permissions.
Potential impact
- Privilege escalation, account attribute tampering, and unauthorized changes to internal state.
Remediation
Use a separate request DTO and explicitly copy only allowed fields into the domain object.
Examples
Before
csharp
currentUser = model;
After
csharp
currentUser.Name = dto.Name;
currentUser.Email = dto.Email;
Explanation:
- Before: Directly binding a request body to a domain object can let attackers overwrite privileged or internal fields.
- After: Bind the request to a DTO and explicitly copy only allowed fields into the domain object.