HomeSecurityVulnerability in popular app "MyFitnessPal" exposed users' personal information

Vulnerability in the popular application “MyFitnessPal” exposed personal user data

Exercise-Tracking_Preview

The popular MyFitnessPal app, which is used by 65 million users, contained a vulnerability that exposed personal information, such as users' dates of birth.

MyFitnessPal allows users to enter personal information, such as their country, state, and city. However, this information could be visible to anyone, according to security researcher Randy Westergren, due to a direct object reference vulnerability in the app.

“Using Fiddler proxy, I began monitoring my own interactions within the Android App, capturing requests being made to the undocumented MyFitnessPal API,” Westergren said

“I noticed an interesting request to this URL: https://api.myfitnesspal.com/v2/users/23662613557054 – a simple request to retrieve information about my user, which seemed like a possible insecure direct object reference.”

Westergren wrote a simple PHP script to test and extract other user data, replacing the sequence of numbers at the end of the URL, and reported the flaw to MyFitnessPal.

The app developers responded immediately and fixed this simple bug within two days from the reporting date.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS