5

Only found this out after the fact, but an almost total lack of authorisation checks in an exposed API has got to be up there.

Comments
Add Comment