| |
Exploiting vulnerabilities in Johnson and Johnson web apps
Security researcher Eaton revealed two critical vulnerabilities in Johnson & Johnson web applications: a campus recruiting system that exposed nearly 1,000 students' personal information due to reliance on a hardcoded API key instead of proper token authentication, and an audit tracking management system used by 20 companies where unauthenticated APIs allowed full access to employee data and administrative functions. Both vulnerabilities exploited weaknesses in client-side authentication implementation where frontend MSAL (Microsoft Authentication Library) tokens were not validated by backend APIs.
Read Full Article →
← More Tech news