India’s Largest Pharmacy Platform Exposed Customer and Internal System Data

Related

Multiple US Healthcare Data Breaches Expose Millions of Patient Records

What happened Several major healthcare data breaches have been added...

Grafana Labs Refuses to Pay Ransom After Codebase Theft

What happened Grafana Labs confirmed over the weekend that an...

UK Water Company Fined After Hackers Lurked Undetected for Nearly Two Years

What happened The UK's Information Commissioner's Office fined South Staffordshire...

Škoda Online Shop Security Incident Exposes Customer Data

What happened Škoda Auto has disclosed a security incident affecting...

Share

What happened

A critical vulnerability in the online platform of Dava India, a division of Zota Healthcare, allowed attackers to create privileged super admin accounts and gain full control of backend systems. The issue, discovered by Eaton-Works, was caused by backend APIs that lacked authentication checks, enabling unauthorized users to reset admin credentials and access internal administrative functions. The exposure included customer order information, store details, and product management capabilities, affecting nearly 17,000 customer orders across 883 stores. Attackers with super admin access could also modify product listings, change pricing, disable prescription requirements, and generate promotional coupons. The vulnerability was reported to CERT-IN and later patched, and researchers confirmed no known personal data theft occurred before remediation. 

Who is affected

Customers and operations of Dava India, particularly those using its online platform and mobile app, are affected, as exposed administrative access allowed visibility into customer orders and internal system management functions. 

Why CISOs should care

The vulnerability demonstrates how insecure API authentication controls can expose sensitive customer and operational data while enabling attackers to manipulate core business systems and administrative functions. 

3 practical actions

  • Audit API authentication controls. Ensure administrative and backend endpoints enforce proper authentication and authorization checks. 
  • Review administrative account creation logs. Identify unauthorized privileged account creation or credential resets. 
  • Monitor system configuration changes. Detect unauthorized modifications to products, pricing, or system settings enabled through privileged access.
IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.