Clothing Retailer Patches Website Flaw Exposing Customer Data
ID: 0e1fe48c-8299-5d60-a064-c58a25bdbc78
STIX ID: report--0e1fe48c-8299-5d60-a064-c58a25bdbc78
Feed Name: TechRepublic Security
Threat Score
A security researcher discovered that Express’ order confirmation pages used sequential order IDs in URLs that could be tweaked to view other customers’ checkout data — including names, emails, phone numbers, postal addresses, order details and the last four digits of payment cards. Express confirmed and patched the issue after the researcher reported it via TechCrunch, but had not publicly notified affected users or fully answered disclosure questions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
