Droom Fixes Security Flaw That Exposed Private Data, Banking Details of Millions

The security flaw in Droom’s system was associated with misconfiguration of the Facebook sign-in API.

Advertisement
By Nadeem Sarwar | Updated: 12 December 2019 09:23 IST
Highlights
  • Droom fixed the patch after Gadgets 360 reached out to them
  • The security lapse exposed phone number, Aadhaar, PAN, and more details
  • Droom’s security flaw also revealed banking details of users

Droom claims to have over 35 million monthly visitors on its platform

Droom, one of India's largest online marketplaces for buying and selling vehicles, has fixed a severe security flaw that was exposing the personal data and banking details of millions of its users. The security glitch, which was associated with misconfiguration of Facebook sign-in API, could provide malicious hackers easy access to user details such as names, addresses, phone numbers, Aadhaar numbers, PAN card numbers, and their purchase history on Droom. Moreover, banking details of users such as the name of their bank, account number, and IFSC code could also be accessed easily by just using the registered email ID of a Droom user.

Independent security researcher, Sayaan Alam, reached out to Gadgets 360 with his findings of the aforesaid security flaw in Droom's system, and also shared with us the PoC of how hackers could exploit the bug to gain access to user data. We were also able to verify Alam's findings by creating a Droom account and completing the user profile by adding fake details in the required fields. All these details such as user name, address, phone number, Aadhaar number, PAN card number, bank account number, purchase history, and more were pulled out in a very short span of time by Alam after exploiting the flaw.

“The issue lay with misconfiguring of Facebook sign-in API. Facebook's authentication gives a site a unique token, which is used to confirm your sign-in details. But due to a misconfiguration, attacker can change their email ID to victim's email ID and this gives him access to other user's account,” Alam told Gadgets 360.

Advertisement

The security flaw essentially allowed access to the entire data on a user's Droom profile
Photo Credit: Sayaan Alam

 

“The bug grants customers' login account access to anyone who knows their email ID—and from there, it's possible to extract a person's full name, address, and phone number, Aadhaar card number, PAN card number, bank account details, wallet balance access, apart from their purchase history with Droom,” added the security researcher, who is still in his teens.

Advertisement

Gadgets 360 reached out to Droom and reported the security flaw to one of its senior software developers. After discussing the bug and its severity with Alam, who also discovered a security lapse in a fashion e-commerce platform called Spoyl last month, Droom fixed the bug later on the same day. 

"Droom takes security, safety and privacy of customer data with utmost level of seriousness and is committed to ensuring complete protection of user data," Amit Goel, VP, Engineering, Droom told Gadgets 360 in a statement.  "We invest heavily and adhere to best practices in our engineering and infrastructure operations. The issue has been fixed and we confirm that no data has ever been compromised. Droom follows very high standards and processes in ensuring complete security of user data."

Advertisement

"Droom uses industry leading solutions like AKAMAI and AWS and have implemented layered security including multifactor authentication and CSRF token wherever required. Further Droom does not store any Credit/Debit card or e-wallet data. All transactions at Droom are executed via 3rd party payment gateways only," Goel added.

As for the company, it has a userbase of 35 million users monthly users. Apart from India, the company has a presence in Malaysia, Singapore, and Thailand as well. As per the company's website, Droom is currently generating $1.3 billion (roughly Rs. 9,212 crores) in annualized GMV and offers services in nearly a thousand Indian cities.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Droom
Advertisement

Related Stories

Popular Mobile Brands
  1. Origin OS 6 Will Soon Replace Funtouch OS in India, Company Confirms
  2. Oppo Find X9 Design, Colours and Hasselblad Cameras Revealed Ahead of Debut
  3. Vivo V60 Lite 5G With MediaTek Dimensity 7360 Turbo SoC Launched: See Price
  4. Amazon Sale 2025: Top Deals and Discounts on 50-Inch Smart TVs
  5. Amazon Sale 2025: Top Deals, Discounts on Laptops Under Rs. 30,000
  6. Oppo A6 Pro 4G With 50-Megapixel Main Camera, 7,000mAh Battery Launched
  7. Xiaomi 17 Pro Max Will be Equipped With This Battery, Display
  8. Amazon Great Sale 2025 Highlights: Deals on iPhone 15, OnePlus 13 and More
  9. Best Offers on Mobiles Under Rs. 10,000 During the Amazon, Flipkart Sales
  1. NASA Selects 10 New Astronauts to Support Future Moon and Mars Missions
  2. Scientists Confirm Ancient Asteroid Impact Created North Sea’s Silverpit Crater 43 Million Years Ago
  3. Comet C/2025 R2 (SWAN) Might Become Visible to the Naked Eye in October: Here's What We Know
  4. Oppo A6 Pro 4G With 50-Megapixel Rear Camera, 7,000mAh Battery Launched: Price, Features
  5. Samsung Galaxy Tab A11 With 8.7-Inch Display, 5,100mAh Battery Launched in India: Price, Specifications
  6. Amazon Sale 2025: Best Deals on Amazon Fire TV Stick, Echo Show and More
  7. CSRC Directs Brokers to Pause Real-World Asset Tokenisation Activity in Hong Kong
  8. Philips TAT1269 TWS Headset Launched in India Alongside Bluetooth and Party Speakers: Price, Features
  9. Facebook Dating Brings an AI Assistant to Help Users Find Prompt-Based Matches
  10. Vivo V60 Lite 5G With 6,500mAh Battery, MediaTek Dimensity 7360 Turbo SoC Launched: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.