IAR-Webops / IITMConnect

Repo for IITM Connect by @yashmurty
http://iitmconnect.iitmadras.in/
6 stars 0 forks source link

Fake Ownership to access Private Data #1

Open yashmurty opened 9 years ago

yashmurty commented 9 years ago

If a malicious user signs in using a new social account, he can link it with any roll number that he provides, and can access the personal information, entered for that roll number, by the genuine user.