Comment oldie but goodie (Score 2) 28
TechCrunch found that the app's backend services didn't properly restrict access, allowing any logged-in user to request and receive data belong to other users.
I *loooove* how common this flaw is. I remember decades back getting hired by a guy to keep working on some event marketing website he'd had another programmer build. Took me like 10 minutes at that job to figure out you could do the exact same thing.