(Choose 1 answer)
Which threat can occur when a POST parameter performs an operation on behalf of a user without checking a shared secret?
A. Cross-site request forgery
B. Insecure direct object reference
C. Cross-site scripting
D. Injection
E. None of the other choices
Exit 26