IDOR is a logic flaw. The attacker isn't "hacking" code; they are simply guessing numbers.
Access customer lists, email addresses, and passwords. inurl index php id 1 shop free