As reported by TechCrunch, fashion retailer Express has addressed a significant security flaw on its website that inadvertently exposed customer order details and personal information to the public.
The vulnerability allowed unauthorized access to order confirmation pages, revealing customer names, phone numbers, email addresses, postal and billing addresses, and details of purchased items. Partial payment card information, including card type and the last four digits, was also exposed. The flaw was discovered by security advocate Rey Bango, who found that by manipulating sequential order numbers in the web address, one could view other customers' order information. At least a dozen customer orders were found listed in search engine results.
Express, now owned by WHP Global, patched the website on Wednesday after being contacted by TechCrunch.
Source: TechCrunch
