Bugs in Lego Resale Site Allowed Hackers to Hijack Accounts
Security analysts have found bugs in Lego's second-hand online marketplace that left its users at risk of account hijacking and data leakage.
In a blog post, Salt Labs said that the issues, now resolved, affected Lego-owned BrickLink.com, the world’s largest official marketplace for Lego bricks.
The security researchers said that two API security issues could have enabled an attacker to take over BrickLink accounts, and access and steal personally identifiable information stored on the site. The vulnerabilities could have also allowed attackers to gain access to internal production data and compromise internal servers, Bleeping Computer reports. The BrickLink bugs were spotted when Salt Lab analysts were experimenting with user input fields on the marketplace site.