AliExpress Website Security Flaw Compromises Sensitive Data of Millions of Users

A serious vulnerability has been uncovered on the popular online marketplace AliExpress, potentially exposing vast amounts of personal information from millions of users globally. This security flaw permits unauthorized access to the private data of hundreds of millions of AliExpress users without the need for account passwords, posing a significant threat to user privacy and security.

AliExpress, which is owned by the Chinese e-commerce giant Alibaba Group, serves over 300 million active users across more than 200 countries. The platform allows users to purchase goods in bulk or individually, often at lower wholesale prices. The newly identified weakness could have far-reaching implications, allowing malicious actors to exploit this data breach effortlessly.

According to reports from cybersecurity researcher Amitay Dan, who specializes in application security at Cybermoon.cc, the vulnerability enables unauthorized individuals to access the shipping and contact details of AliExpress users merely by altering the URL parameters linked to the website’s address modification feature. Dan disclosed this critical flaw to The Hacker News after first informing the AliExpress security team and establishing communication with Israeli media outlets.

The vulnerability arises in a segment of the website where logged-in users can manage their shipping addresses and contact information through specific URLs. By exploiting a minor oversight in the validation mechanism, an attacker could modify the “mailingAddressId” in the URL, effectively retrieving sensitive information tied to a different user’s account without any authentication barriers. For instance, changing the numerical value at the end of the URL could yield the addresses belonging to multiple users sequentially—an approach that can be automated through scripting.

An adept cybercriminal could leverage this vulnerability not only to gather personal data from a few accounts but potentially from millions by systematically querying the “mailingAddress.htm” page with various “mailingAddressId” values. Such a brute-force method could exploit the flawed endpoint, leading to substantial privacy violations across the platform.

Following his findings, Dan indicated that measures are being taken by the AliExpress team to address and patch this vulnerability imminently. While the exact timeline for the deployment of the fix remains unclear, the urgency of the situation highlights the ongoing challenges faced by major online platforms in securing user data against potential breaches.

In terms of cybersecurity frameworks, the tactics involved in this incident may include initial access techniques, coupled with data exfiltration strategies as outlined in the MITRE ATT&CK Matrix. Specifically, tactics related to initial access could pertain to the adversary’s ability to manipulate URL parameters to gain access to sensitive data without prior authentication. Efforts to maintain persistence and escalate privileges within the platform could also have been represented in a broader attack pattern, emphasizing the critical need for improved validation mechanisms in user authentication processes.

As the landscape of cybersecurity continues to evolve, AliExpress and similar platforms are reminded of the necessity of stringent security protocols and regular assessments to safeguard against vulnerabilities that could compromise user data on a massive scale. Business owners and cybersecurity professionals alike should remain vigilant regarding these developments, understanding the implications for personal information security amid the increasing complexity of cyber threats.

Source link