30 Apr 2021

API Hole on Experian Partner Site Exposes Credit Scores

A Rochester Institute of Technology sophomore discovered a vulnerability on a partner website of Experian that allows anyone to look up credit scores with a name and mailing address. Bill Demirkapi found the leak when he was looking for information about student loan vendors online.  He discovered the code behind

