An error on the United Airlines website allowed anyone to access the information of travelers who requested a refund.
The airline’s website allows users to check the status of their refund by entering their ticket number and last name. But the site does not validate the last name, which allows access to other travelers’ refund information by changing the ticket number.
See also: United Airlines eliminates charges for flight changes.
Computer security expert Oliver Linow, who found the error, told TechCrunch he could see travelers’ last names, the type of payment and currency used to purchase the ticket, and the amount of the refund.
Linow said he reported the problem to United on July 6. The airline took a month to fix it.
Related Topics
Qantas announces new route: Sydney and Las Vegas to be Connected for First Time via Direct Flights
FAA Issues Airworthiness Directive for Boeing 737 MAX Due to Risk of Excessive Cabin Temperatures
American Airlines Invests US$1 Billion to Transform Concourse D at Miami International Airport
Pratt & Whitney Strengthens Industrial Capacity in Georgia: $200 Million Investment to Boost GTF and F135 Engine Programs
Líder en noticias de aviación