HomeNewsTrendsExclusive: Security breach on Pepperfry exposes details of users; now plugged
Trending Topics

Exclusive: Security breach on Pepperfry exposes details of users; now plugged

Security researcher Ehraz Ahmed found the bug on Pepperfry's website, which could have led to the security flaw.

September 06, 2019 / 21:55 IST
Story continues below Advertisement

A major security flaw was detected on online furniture store Pepperfry's website, which could have allowed users to sign in to another registered user's account. Pepperfry has claimed that the bug was fixed within an hour of being detected.

Security researcher Ehraz Ahmed found the bug on Pepperfry's website, which could have led to the security flaw. Speaking exclusively to Moneycontrol, Ahmed said that the bug could allow a user to log into another user’s account and/or create a new account of any user, which does not exist.

Story continues below Advertisement

The flaw was with the website's 'Internal Authentication' Application Program Interface (API), which allowed users to auto-login. The same API showed personal information of users such as their name, address, contact number etc.

User details listed after Ahmed entered the email id