Mass assignment
Binding incoming request data directly onto an internal object lets somebody set fields you never meant to expose.
The form shows name and email; the object also has isAdmin and accountBalance. Sending those extra fields sets them, because the framework was told to map everything. It is a convenience feature that silently becomes an authorisation flaw, and the fix is listing what may be bound rather than what may not.
Checked against the primary source.
