Mass assignment

Binding incoming request data directly onto an internal object lets somebody set fields you never meant to expose.

The form shows name and email; the object also has isAdmin and accountBalance. Sending those extra fields sets them, because the framework was told to map everything. It is a convenience feature that silently becomes an authorisation flaw, and the fix is listing what may be bound rather than what may not.

Checked against the primary source.

More on Application security