GraphQL API authorization flaw found in major B2B financial platform

Salt Labs says other platforms handling sensitive information tend to make the same mistakes.