/api/v1/users — List all users (no auth required)
/api/v1/users/{id} — Get user by ID (IDOR)
/api/v1/users?search= — Search users (SQL injectable)
/api/v1/users/{id} — Update user (mass assignment)
/api/v1/orders/{id} — Get order (IDOR)
/api/v1/config — API configuration (info disclosure)