Including the unique token in a hidden field can be an effective method for preventing this kind of risk:
Insecure Direct Object References
Insecure Cryptographic Storage
Unvalidated Redirects and Forwards
Cross-Site Request Forgery (CSRF)