After the special 100th edition last week, which was all about API security advice from the industry’s thought leaders, this week we are back to our regular API security news, and we have twice the number of them, from the past two weeks.

Vulnerability: Giggle

Giggle is a women-only social network and mobile app. It is meant to be a safe place for everyone on the network but, turns out it was not all that safe: researchers from Digital Interruption found some serious API flaws in it.

The team ran the app through a proxy and observed the API traffic. They found that the API behind the app effectively had a query language:

This meant that they could query any user record:

The API returned full user info, even when the queried record was another user (classical BOLA/IDOR):

#security #integration #api #cybersecurity #apis #api security #api vulnerabilites #api newsletter #security newsletter

API Security Weekly: Issue #101
1.40 GEEK