The SecOps Group Related Exams
CAP Exam

GraphQL is an open-source data query and manipulation language for APIs, and a query runtime engine. In this context, what is GraphQL Introspection?
After purchasing an item on an e-commerce website, a user can view his order details by visiting the URL:
A security researcher pointed out that by manipulating the order_id value in the URL, a user can view arbitrary orders and sensitive information associated with that order_id.
Which of the following is correct?