Executive brief
Hiperdino's REST API contains a flaw in the 'customer/check' endpoint that allows attackers to look up customer contact information (email and phone numbers) without proper access controls. Although a static bearer token is required, the endpoint lacks rate limiting and proper error handling, making it possible for an attacker with the token to enumerate customer contact details and expose personally identifiable information.
Technical details
The vulnerability is an inadequate access control issue in the 'customer/check' endpoint of Hiperdino's REST v1.0 API. The endpoint accepts a telephone number or email address as input and returns associated customer information (email and phone) when a match is found. The vulnerability requires possession of a valid static bearer token (weak authentication control), but lacks rate limiting and generic error handling to prevent enumeration attacks. An authenticated attacker can systematically query the endpoint with different phone numbers or email addresses to discover registered customer contact details, leading to information disclosure.
Affected products
- Hiperdino REST API v1.0
Timeline
- 2026-09-14: disclosed