Programmer DD
Jun 3, 2023 · Information Security
How a Simple API Parameter Leak Exposed Thousands of Student Records
This article details the discovery and exploitation of an API‑based information leakage in a university system, showing how default passwords, missing parameters, and directory depth allowed an attacker to retrieve thousands of student records, and concludes with lessons for security testing.
API vulnerabilitydata exposureinformation leakage
0 likes · 10 min read
