CoopCycle Leak Exposes Thousands of Customer Addresses via Unchecked GET Endpoint
A missing security expression on the `/api/stores/{id}/addresses` collection endpoint let any authenticated CoopCycle user enumerate store IDs and harvest full names, street addresses, and postcodes, compromising privacy across multiple cooperatives.