Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social  路  activity timestamp 3 weeks ago

We found the bug in how Vetco generates PDF documents for its customers. Its PDF page was public and was indexed by Google, which is how we found it. Worse, an IDOR bug in the URL meant it was possible for anyone to obtain customer data by changing the customer's unique ID by a single digit. 馃う

https://techcrunch.com/2025/12/10/petco-takes-down-vetco-website-after-exposing-customers-personal-information/

TechCrunch

Exclusive: Petco takes down Vetco website after exposing customers' personal information

TechCrunch found Petco's veterinary clinics were spilling customers' personal information and medical histories of their pets to the open web.
Jan Wildeboer 馃樂:krulorange:
Jan Wildeboer 馃樂:krulorange:
@jwildeboer@social.wildeboer.net replied  路  activity timestamp 3 weeks ago

@zackwhittaker #WhereIsMySurprisedFace

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.1-alpha.44 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct