A Tale of Two Routes

from blog Aleksandr Hovhannisyan, | ↗ original
Poorly designed API routes and an account creation loophole allow Twitter users to hijack routes.