Emerging Indian social media startup Slick exposed for months an internal database storing users’ personal information, including information on school-aged children.

Since at least December 11, a database including the complete names, mobile phone numbers, birth dates, and profile images of Slick members was left unprotected online.

Bengaluru-based Archit Nanda, a former executive at Unacademy, established Slick in November 2022 after turning away from cryptocurrencies and closing his previous firm, CoinMint. His most recent endeavour, Slick, is available on both Android and iOS and functions similarly to Gas, a successful U.S. app based on compliments. The application also enables high school and college students to converse with and about their friends incognito.

Anurag Sen, a security researcher, discovered the unsecured database and requested TechCrunch’s assistance in reporting the matter to the social media startup. Slick protected the database shortly following TechCrunch’s Friday inquiry.

Due to a misconfiguration, anyone with knowledge of the database’s IP address was able to access the database, which had more than 153,000 user entries at the time it was secured. TechCrunch also discovered that the database was accessible via an easily guessed subdomain on Slick’s main website.

The researcher also alerted India’s computer emergency response team, often known as CERT-In, which is the country’s primary cybersecurity body.

Nanda confirmed to TechCrunch that Slick has resolved the vulnerability. It is unknown whether anyone except Sen discovered the database before it was secured.

Upon its debut in India last year, Slick quickly garnered a large number of younger users. Nanda announced on Twitter earlier this month that the app had surpassed 100,000 downloads.

Related Articles:

Ways Parents Can Help Their Children Break Free From Technology Addiction

Google, Microsoft and 15 other technology companies headed by Indian-origin executives

Winner of America’s Next Top Model Deletes Twitter Account Following The Last of Us Star Puts an End to Them

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

New Apple Updates Could Prevent Air Tag Stalking

AirTag stalking has been an ongoing issue since the product’s introduction. The…

Atari Just Bought a Lot of Old Video Game IPs from the 1980s and 1990s.

Atari bought the intellectual property rights to more than 100 PC and…

Hacker Discovers Flaw that Enables Anyone to Circumvent Facebook 2FA

The 404 not found HTTP status code indicates that the page you…

The Best Controllers from 8BitDo Can Now Be Used With iPhones, iPad, and Other Apple Products.

8BitDo has released a new firmware update for some of its wireless…