A security flaw at DavaIndia Pharmacy allowed attackers to access customers’ data and more
ID: 8184f980-3f3a-5902-aace-944f78ff33be
STIX ID: report--8184f980-3f3a-5902-aace-944f78ff33be
Feed Name: Security Affairs
A security researcher discovered an exposed admin subdomain and unauthenticated super-admin APIs on DavaIndia Pharmacy, enabling creation of a super-admin account and full administrative access; this allowed viewing and editing of customer orders and personal data, manipulation of stores, inventory, coupons (including generating 100% discounts), and potentially bypassing prescription controls. The issue was reported on August 20, 2025, fixed within a month, and confirmed closed with CERT-In on November 28, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
