Is Dil Ka Rishta safe as technical glitch in API Exposed Data of over 5,000 users?

Is Dil Ka Rishta Safe As Technical Glitch In Api Exposed Data Of Over 5000 Users

KARACHI – In Pakistan’s growing online Matrimonial market, Dil Ka Rishta remains among top choices as it made huge branding on digital rishta solution, until now, as a recent API flaw and misconfigured Cloud Storage allegedly exposed data of more than 5000 users. The report suggests that the exposed data includes a wide range of personally identifiable and sensitive attributes. These reportedly include full names, phone numbers, dates of birth, marital status, and other details.

As per reports, a serious data privacy concern involving Dil Ka Rishta claimed that a vulnerability in its mobile API may have exposed the personal information of around 5,600 users.

The issue stems from an Insecure Direct Object Reference (IDOR) vulnerability. In simple terms, this occurs when an application exposes internal identifiers, such as sequential numeric profile IDs, without properly checking whether a requesting user is authorized to view the corresponding data. By manipulating these IDs in API requests, an attacker could potentially access other users’ profiles without authentication.

The platform’s backend, described as Laravel-based, is alleged to have lacked sufficient authorization validation at the API layer. As a result, user profiles could reportedly be accessed in sequence by incrementing numeric identifiers, effectively enabling systematic retrieval of stored records.

A user named itsRdhere exposed this on Telegram, as he claims that the system did not implement adequate rate limiting. This type of control is typically used to prevent automated abuse by restricting how frequently a single user or script can make requests. Without it, large-scale automated scraping becomes significantly easier.

The report suggests that the exposed dataset includes a wide range of personally identifiable and sensitive attributes. These reportedly include full names, phone numbers, dates of birth, marital status, religious affiliation, caste and ethnicity details, educational qualifications, professional information, income-related data, and profile photographs.

Of particular concern is the claim that profile images were stored in an Amazon S3 bucket configured without proper access restrictions. In misconfigured cloud environments, such storage buckets can become publicly accessible, meaning files can be retrieved directly via URL without authentication. If accurate, this would have allowed unrestricted downloading of user profile images.

Security researchers frequently emphasize that APIs are now one of the most commonly exploited components in modern applications. Unlike traditional web interfaces, APIs often directly expose backend data structures, making them highly sensitive to design flaws.

The recent development raised questions as Dil Ka Rishta got over 7 million downloads and hosts millions of user profiles, including many that are verified for authenticity. It primarily serves users in Pakistan but also has a strong presence among the Pakistani and Muslim diaspora in countries such as the UK, UAE, and Canada.

The app’s key goal is to alter traditional arranged marriage systems by combining cultural practices with digital tools. The app offers features such as strict profile verification, AI-based matchmaking, advanced search filters (including city, profession, education, and community preferences), and privacy-focused messaging tools. It also allows family members or parents to manage profiles on behalf of candidates, reflecting traditional matchmaking customs.

It also provides both free basic services and a premium VIP matchmaking option where experts manually select and introduce suitable matches. Available on Android and iOS as well as through its official website.

StormFiber website hacked by Indian hackers

Get Alerts