logo

Indian pharmacy chain giant exposed customer data and internal systems

ID: b1423c13-9be9-5e55-a0d6-0c5a65c40ad5

STIX ID: report--b1423c13-9be9-5e55-a0d6-0c5a65c40ad5

Feed Name: TechCrunch Security News

Threat Score
65/100

Date Published: 2026-02-14

Date Updated: 2026-04-23

Author: Jagmeet Singh

...
...

A security researcher discovered insecure “super admin” administrative APIs on DavaIndia Pharmacy’s website that allowed unauthenticated creation of high-privilege accounts, exposing nearly 17,000 online orders and administrative controls across 883 stores; the issue, present since late 2024, was reported to CERT-In in August 2025 and patched within weeks with no evidence of prior exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.