Insecure Shopify plugin exposed hundreds of stores| Cybernews (cybernews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 16 Jul 12:17
https://sh.itjust.works/post/42251935

#cybersecurity

threaded - newest

Alphane_Moon@lemmy.world on 16 Jul 15:27 collapse

The Consentik plugin adds cookie consent banners to customer websites. However, the unsecured server was broadcasting real-time site analytics and private authentication tokens, including Shopify admin credentials and Facebook ad tokens, to anyone on the internet who knew where to look.

This is brutal.