Now SQL injection flaw found on Tesco website
Yet another vulnerability on the Tesco website has been confirmed by a researcher, who lambasted the supermarket giant for its “unprecedented” silence on fixing various security issues.
Following claims that Tesco is not hashing, salting or encrypting customer passwords, and has an XSS flaw on its main website, customers and onlookers have bemoaned the company’s lack of action.
There has been no confirmation that fixes have been implemented and the issues had not been addressed at the time of publication, whilst data protection watchdog the Information Commissioner’s Office (ICO) is looking into the matter. But now another vulnerability on the Tesco website has been uncovered and verified, said security expert Troy Hunt, which could place the firm and its customers at risk. The flaw was highlighted in the comments section of one of Hunt’s blog posts.
