Devs - once again, know the difference between a trusted and untrusted input.
UX people - sometimes devs make things slightly more complex than you'd like them to be on purpose.
A number of e-ticketing systems allowed third parties to view, and in some cases even change, a user's flight booking details, or print their boarding passes.
https://betanews.com/2019/02/06/airline-eticketing-passenger-risk/