Get a Pentest and security assessment of your IT network.

Cyber Security

Louis Vuitton fixes data leak and account takeover vulnerability

Louis Vuitton has quietly patched a security vulnerability on its website that allowed for user account enumeration and even allowed account takeover via password resets. The vulnerability is surprisingly easy to exploit and I had found it by accident when clicking in one of the links in the. MyLV account section of the company’s website. An attacker can potentially obtain email addresses of multiple. members without their knowledge or consent by. simply enumerating their account ID in the URL. The company thanked the researcher for reporting the vulnerability in an email.

Source: https://www.bleepingcomputer.com/news/security/louis-vuitton-fixes-data-leak-and-account-takeover-vulnerability/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security