Indian Pharmacy Giant Exposes Customer Data
Executive Summary
A major Indian pharmacy chain, DavaIndia, inadvertently exposed sensitive customer data and internal administrative controls due to a backend flaw in its web dashboards. The vulnerability, discovered by a security researcher, allowed potential access to thousands of online orders.
Attack Overview
- Attack Path: Insecure "super admin" application programming interfaces (APIs) allowed unauthenticated access to backend systems, potentially enabling the creation of privileged accounts.
- Attacker: The vulnerability was discovered and reported by independent security researcher "Zveare".
Impact Assessment
- Data Exposed: Nearly 17,000 online orders were potentially accessible, including customer PII and drug purchase history.
- Critical Risk: The flaw also allowed unauthorized users to toggle "Prescription Required" status for drugs, creating a significant public safety and regulatory liability.
Strategic Takeaway
This incident highlights the critical need for robust security controls on administrative interfaces, as a single misconfiguration can lead to widespread data exposure.
Relevant professional terms
- Backend
- The part of a software application that is not visible to the user, handling server-side operations, logic, and data management.
- API (Application Programming Interface)
- A set of rules and protocols that allows different software applications to communicate with each other.
Source: TechCrunch
