← Back to feed
Vulnerabilities & PatchesEmerging1 sourceMar 5, 2023 · 16:22via API Security News

Issue 215: API flaws in Lego marketplace, API style guides, 42Crunch joins MISA

Brief

This week, we have news of API and web security flaws in the Lego marketplace, potentially allowing for a full account takeover. From NordicAPIs, we have a guide to seven examples of quality API style guides and coverage of the recent news from 42Crunch being admitted to the Microsoft Intelligent Security Association (MISA).

Finally, we have details of another addition to the burgeoning collection of deliberately vulnerable API applications.

Vulnerability: API flaws in the Lego marketplace risk user data

First up this week is some excellent research from Shiran Yodev ( @shrnyo ) into a series of vulnerabilities on the Lego platform, which, if exploited by a skilled attacker, could have led to an account takeover. The vulnerabilities were responsibly disclosed to Lego, who took immediate steps to address the issues found; no known exploits are known to have taken place.

Read more on API Security News