Bitquark, a security researcher, discovered a vulnerability that allowed SQL Injection on the official Tesla Motors website. Fortunately, the company reacted immediately and closed the security gap on its website immediately after its existence was disclosed.
Initially, the expert found some cross-site scripting (XSS) vulnerabilities on Tesla's website. However, after a later update, he discovered a bug that allowed SQL Injection on Tesla Motors' design studio page, which allowed customers to customize their car before ordering it.
The flaw was in the URL shortener used by customers to share their created configuration with their friends. The vulnerability left the backend database, which included the company's customer records and administrator credentials, exposed.
Tesla managed to fix the problem after obtaining the technical details and a Python script from the security researcher which he used to exploit the vulnerability.
Additional information is available on the Bitquark blog.


