Indian pharmacy chain giant exposed customer data and internal systems


  • DavaIndia Pharmacy flaw allows unauthenticated users to create “super admin” accounts with full privileges
  • Exposed sensitive customer data related to orders, including health status, medications, and personal information
  • Bug responsibly disclosed in 2024, fixed at the end of 2025; no evidence of malicious exploitation, customer data is likely secure

A major Indian pharmacy chain operated a faulty platform that exposed the highly sensitive data of millions of users, experts have warned.

DavaIndia Pharmacy, the pharmaceutical arm of Zota Healthcare, currently operates over 2,300 stores across the country. However, its platform was bugged to allow unauthenticated users to create “super-admin” accounts.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top