Indian pharmacy chain giant exposed customer data and internal systems
The issue affected DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, which operates a large network of retail outlets across India. Security researcher Eaton Zveare told TechCrunch that he discovered the flaw after identifying insecure “super admin” application programming interfaces on DavaIndia’s website and privately shared details with Indian cybersecurity authorities.
The bug is now fixed, and Zveare disclosed his findings.
The exposure comes as Zota Healthcare rapidly scales DavaIndia Pharmacy’s retail business.
Zveare told TechCrunch that the flaw stemmed from insecure admin interfaces, which allowed unauthenticated users to create “super admin” accounts with high privileges.
“Customer information was linked to their orders,” said Zveare.
“This includes name, phone numbers, email IDs, mailing addresses, total amount paid, and the products purchased. Since this is a pharmacy, the products being purchased could be considered private and even embarrassing for some people.
Sujit Paul, chief executive of Zota Healthcare, did not respond to emails sent by TechCrunch last month.
The researcher said there was no indication the flaw had been exploited before it was patched
Logic Quality Breakdown:
- Updated_At:
- Truth_Blocks:
- Analysis_Method: