2 min read
[Insufficient Authorization] Unauthenticated Delivery-Order API Exposes Other Customers' Personal Data
Masked FVE record: a null accessToken was accepted and order IDs increased sequentially, so anyone could read other customers' phone numbers, names and payment methods without authentication.
Read full article