shall we all assume it was an sql injection? does anyone know what the actual vulnerability was?
For it to be a SQL injection, he'd have to have been looking for vulnerabilities.
API not validating correctly. If this is true, it will take a long time to fix.