>Vendor stores database IDs in cookies which are easily spoofed (USERID_COOKIE), allowing all user information to be accessed.
If this means what I think it means, why did it take until 2013 for this to be discovered?
If this means what I think it means, why did it take until 2013 for this to be discovered?