Faulty Shopify plugin puts hundreds of websites at risk of invasive attacks – find out how to stay safe




  • Consentik, a cookie consent & consent management app for Shopify, kept sensitive data in an open archive
  • The archive was available for at least 100 days, if not more
  • It included site analytics data, Shopify Personal Access Tokens, and Facebook Auth Tokens

A major, reputable Shopify plugin, was leaking sensitive information for months, exposing hundreds of ecommerce businesses to all sorts of risks, experts have warned.

Security researchers from Cybernews spotted the leak and helped plug the hole, having discovered a publicly accessible Kafka server which was holding sensitive data from Consentik.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *