Review reveals distinct failure boundaries and uneven automated detection across major web vulnerability classes, highlighting the need for targeted, boundary-specific security controls.
A typical web application consists of a browser, aserver, a database, and often an identity provider or third-partyservice, and any transition between these components is a placewhere trust assumptions can break down. This paper reviewsfive vulnerability families that exploit different handoffs: SQLInjection (SQLi), Cross-Site Scripting (XSS), Cross-Site RequestForgery (CSRF), Broken Access Control, including InsecureDirect Object References (IDOR), and Authentication and SessionManagement failures. Based on peer-reviewed work from 2021–2025 alongside current OWASP guidance, the review comparesthe five families along a consistent set of dimensions: root cause,attack preconditions, target, detection approach, mitigation, andremaining gaps. SQLi and XSS both arise when untrusted datais allowed to control an interpreter—a database engine in onecase, a browser in the other—and are addressed by keepingdata separate from code and by encoding output for the contextit lands in. Classical CSRF is different: it does not requirea malicious request payload; instead, it exploits the browser’sautomatic inclusion of authentication credentials, which is whyrequest-intent validation and browser cookie policies are centraldefenses. Broken access control usually occurs when authoriza-tion checks are missing, incomplete, or applied inconsistentlyacross endpoints, while authentication and session failures arisefrom weaknesses in identity verification or across the login-to-logout lifecycle rather than any single missing flag. The reviewedempirical studies show uneven automated detection coverageacross vulnerability classes, while browser-level protections suchas SameSite reduce risk without eliminating it. The paper arguesthat these are structurally distinct failures, so they need controlsplaced at the specific boundary each one violates rather than asingle generic control.
No takes yet. Share an insight, caveat, or question.
Arta Danesh (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: