tech12 and Ice covered a serious vulnerability discovered by security researcher Lior Ben-David in the receipt links of payment processor Cardcom: by guessing the parameter at the end of a receipt URL, anyone could access tens of thousands of transaction receipts containing ID numbers, e-mail addresses, phone numbers, home addresses and the last digits of credit cards — data usable for phishing, fraud and even extortion.

Ben-David reported the flaw to the company with a demo video and remediation suggestions; Cardcom said the vulnerability was fixed and had not been exploited.

🇮🇱 לקריאת הפוסט בעברית