DEV Community

Discussion on: What Are Some of the Worst Security Practices You’ve Ever Seen in Software Development?

Collapse
 
aarone4 profile image
Aaron Reese

Order tracking website where the user account was a URL parameter with no password/token. You could see order details for any and all of their customers including delivery address and what was in the order.