Security analysts have discovered two API security vulnerabilities in BrickLink, the LEGO Group's official online marketplace for used and vintage LEGO bricks.

With over one million members, BrickLink is the largest global community of LEGO fans.
Two API security issues discovered by Salt Security could allow an attacker to take over member accounts, gain access to and steal personally identifiable information (PII) stored on the platform, or even gain access to internally generated data and compromise internal servers.

API vulnerabilities, an in-depth analysis
During the exploration of the BrickLink website, the Salt Security team of analysts discovered potential vulnerabilities located in user input fields.
The first is a cross-site scripting (XSS) flaw in the “Find Username” dialog box of the coupon search section, which would allow an attacker to inject and execute code on the target computer using a specially crafted link.

By exploiting the Session ID exposed on a different page, an attacker can use the XSS vulnerability to compromise and gain access to the user's account.
Accessing the account means exposing all data stored on the platform, including personal information, email address, shipping address, order history, coupons, feedback received, desired items, and message history.
The second bug discovered was on the “Upload to Wanted List” page, where users have the ability to upload XML lists of LEGO parts they hope to find and purchase.
Exploiting a problem in the endpoint parsing system, Salt Security analysts launched a successful XML External Entity (XXE) injection attack and included a reference to an external entity in their file.
The XXE attack allowed them to read files on the web server and perform a server-side request forgery (SSRF) attack, which could lead to the extraction of AWS EC2 tokens for the server.
After being alerted by security researchers to the vulnerabilities discovered, LEGO acted quickly and resolved all issues immediately.
See also: HTML smuggling technique uses SVG files and distributes QBot
Regarding the LEGO company: Overall, playing with Lego is great for both kids and adults! Not only does it provide hours of entertainment, but it also has many hidden benefits that help develop important skills, such as fine motor skills, problem-solving abilities, creativity, imagination, patience, and perseverance – all useful traits, regardless of the career path someone chooses later in life! So, if you’re looking for an engaging way for your child (or yourself!) to have fun and learn something new at the same time, then definitely consider getting a LEGO set! You won’t regret it!
See also: NoReboot bug: Undetectable iPhone Backdoor reminiscent of Predator
Cyberattacks are becoming increasingly prevalent, and the retail sector is a particularly attractive target for them due to the emphasis placed on generating revenue as opposed to enhancing security.
To stay secure when shopping, it is essential to use strong account login credentials and enable two-factor authentication, whenever available. Additionally, for increased security when ordering online, we recommend using a guest account or a virtual/temporary payment card, if possible.
Information source: bleepingcomputer.com
