API Security Weekly: Issue #15

This week, there was a major vulnerability in Fortnite sign-in API that allowed attackers to get full access to profiles of players who would click a specifically constructed hyperlink. Plus, we look into best practices for avoiding SQL injections in NoSQL databases and TLS man-in-the-middle attacks.

Vulnerabilities

A team from Check Point Research reported a serious vulnerability in Fortnite authentication API: