DavaIndia Pharmacy, the retail arm of Gujarat-headquartered Zota Healthcare, was scaling hard — more than 2,300 stores across India, 276 new outlets announced in January, and plans for another 1,200 to 1,500 within two years. Its website, security researcher Eaton Zveare found, was running insecure 'super admin' application programming interfaces.

The flaw let unauthenticated users create super-admin accounts with high privileges. From there, an attacker could view thousands of online orders containing customer information, modify product listings and prices, create discount coupons, change which medicines required a prescription, and edit site content — enough for defacement or disruption.

Zveare reported the issue to CERT-In, India's cyber-emergency agency, in August 2025. The vulnerability was fixed within weeks, though company confirmation reached the authorities only in late November. TechCrunch's emails to Zota CEO Sujit Paul went unanswered; there was no indication the flaw had been exploited before it was patched.

Rapid store expansion outran security review — the vulnerable interfaces shipped with the platform and stayed live since late 2024.

Pharmacy purchases are sensitive by default: order data can reveal health conditions and embarrassing purchases even without misuse.

An unauthenticated admin-creation endpoint is a single-fix class of bug that should never survive a year in production.

Admin surfaces are attack surface: a pharmacy's order data is health data, and an unauthenticated create-admin endpoint is an unlocked dispensary.

The bug was fixed within weeks of the August 2025 CERT-In report, with confirmation provided to cyber authorities in late November 2025; the researcher disclosed after the fix.

FOLLOW THE EVIDENCE

The sources

  1. Indian pharmacy chain giant exposed customer data and internal systems techcrunch.com