A security lapse by one of India’s largest pharmacy chains allowed outsiders to gain full administrative control of its platform, exposing customer order data and sensitive drug-control functions, TechCrunch has exclusively learned.
The issue affected DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, which operates a large network of retail outlets across India. Security researcher Eaton Zveare told TechCrunch that he discovered the flaw after identifying insecure “super admin” application programming interfaces on DavaIndia’s website and privately shared details with Indian cybersecurity authorities.
The bug is now fixed, and Zveare disclosed his findings.
The exposure comes as Zota Healthcare rapidly scales DavaIndia Pharmacy’s retail business. The Gujarat-headquartered company operates more than 2,300 DavaIndia stores across India, including 276 new outlets announced in January, and plans to add another 1,200 to 1,500 over the next two years.
Zveare told TechCrunch that the flaw stemmed from insecure admin interfaces, which allowed unauthenticated users to create “super admin” accounts with high privileges.
With that level of access, an attacker could view thousands of online orders containing customer information, modify product listings and prices, create discount coupons, and change settings governing whether certain medicines required a prescription, the researcher said.
Based on system timestamps, Zveare said the vulnerable administrative interfaces appeared to have been live since late 2024. The access exposed nearly 17,000 online orders and administrative controls spanning 883 stores, he said, allowing changes to product pricing, prescription requirements, and promotional discounts. Zveare said the access allowed edits to website content that could have been used for defacement or disruption.
Pharmacy order data can be particularly sensitive, as it may reveal information about a person’s health conditions, medications or other private purchases. Exposure of such data, even without evidence of misuse, carries heightened privacy and patient-safety risks compared with other consumer information.
“Customer information was linked to their orders,” said Zveare. “This includes name, phone numbers, email IDs, mailing addresses, total amount paid, and the products purchased. Since this is a pharmacy, the products being purchased could be considered private and even embarrassing for some people.”
Zveare said he reported the issue to CERT-In, India’s national cyber emergency response agency, in August 2025. The vulnerability was fixed within weeks, though confirmation from the company took longer and was provided to the cyber authorities in late November, he said.
Sujit Paul, chief executive of Zota Healthcare, did not respond to emails sent by TechCrunch last month. The researcher said there was no indication the flaw had been exploited before it was patched.
Source link
#Indian #pharmacy #chain #giant #exposed #customer #data #internal #systems #TechCrunch

![Hey Dave Filoni, Leslye Headland Is Still Down for ‘The Acolyte’ Season 2
No matter what you thought about The Acolyte season one, there is no denying that season two was going to be incredible. Creator Leslye Headland and her team ended that first season with the promise of exploring multiple Dark Side relationships, the reveal of potentially the ultimate Sith in Darth Plagueis, a deep dive into the corruption of the Jedi, and even Yoda’s complicity in it. But, of course, that didn’t happen. Instead, Disney decided not to move forward with more episodes of The Acolyte. A true disappointment to fans of the show, but not all that surprising. The show, of course, had invited all manner of vitriol, and it seems like viewership didn’t quite justify the cost of more episodes. However, in the years since, the show has endured. In fact, just recently, there were reports that it once again cracked the top 10 on Disney+. And, in a new interview, Headland said that she’d still be interested in returning to a galaxy far, far, away. “I would still want to do it! Absolutely,” she told Empire, via Fantha Tracks. “As more people discover it, I think people may want to see some form of the story come back. We did have a lot of stuff that we wanted to explore, including tying in lore to the sequels. Getting into who exactly Manny [Jacinto]’s character is, his connection with [Jedi Master] Vernestra, his connection with [Sith Lord] Plagueis, and then his connection with other sequel-established things.”
Headland went on to say that she’s also felt the show returning a bit in recent days. “I’m having a resurgence of The Acolyte in my real life,” she said. “I speak with people who are really big fans, and were disappointed in the cancellation. was like, I went to a play last night, and somebody ‘I just have to tell you that I loved it.’”
We loved it too and think a second season would be absolutely incredible. Who wouldn’t want to see The Stranger with his new apprentice, and how that works with his master, Plagueis? Or what lengths the Jedi will go to in order to cover it all up? Hey, Lucasfilm president Dave Filoni, take note! Want more io9 news? Check out when to expect the latest Marvel, Star Wars, and Star Trek releases, what’s next for the DC Universe on film and TV, and everything you need to know about the future of Doctor Who. #Hey #Dave #Filoni #Leslye #Headland #Acolyte #SeasonDave Filoni,Leslye Headland,Star Wars,The Acolyte Hey Dave Filoni, Leslye Headland Is Still Down for ‘The Acolyte’ Season 2
No matter what you thought about The Acolyte season one, there is no denying that season two was going to be incredible. Creator Leslye Headland and her team ended that first season with the promise of exploring multiple Dark Side relationships, the reveal of potentially the ultimate Sith in Darth Plagueis, a deep dive into the corruption of the Jedi, and even Yoda’s complicity in it. But, of course, that didn’t happen. Instead, Disney decided not to move forward with more episodes of The Acolyte. A true disappointment to fans of the show, but not all that surprising. The show, of course, had invited all manner of vitriol, and it seems like viewership didn’t quite justify the cost of more episodes. However, in the years since, the show has endured. In fact, just recently, there were reports that it once again cracked the top 10 on Disney+. And, in a new interview, Headland said that she’d still be interested in returning to a galaxy far, far, away. “I would still want to do it! Absolutely,” she told Empire, via Fantha Tracks. “As more people discover it, I think people may want to see some form of the story come back. We did have a lot of stuff that we wanted to explore, including tying in lore to the sequels. Getting into who exactly Manny [Jacinto]’s character is, his connection with [Jedi Master] Vernestra, his connection with [Sith Lord] Plagueis, and then his connection with other sequel-established things.”
Headland went on to say that she’s also felt the show returning a bit in recent days. “I’m having a resurgence of The Acolyte in my real life,” she said. “I speak with people who are really big fans, and were disappointed in the cancellation. was like, I went to a play last night, and somebody ‘I just have to tell you that I loved it.’”
We loved it too and think a second season would be absolutely incredible. Who wouldn’t want to see The Stranger with his new apprentice, and how that works with his master, Plagueis? Or what lengths the Jedi will go to in order to cover it all up? Hey, Lucasfilm president Dave Filoni, take note! Want more io9 news? Check out when to expect the latest Marvel, Star Wars, and Star Trek releases, what’s next for the DC Universe on film and TV, and everything you need to know about the future of Doctor Who. #Hey #Dave #Filoni #Leslye #Headland #Acolyte #SeasonDave Filoni,Leslye Headland,Star Wars,The Acolyte](https://gizmodo.com/app/uploads/2026/06/Acolyte-star-wars-lightsabers-1280x853.jpg)
Post Comment