I keep getting pinged by SMS spam, allegedly by my GP, to go to a site to enter ethnicity data. A phone call to the GP confirms that this if kosher within a very restricted sense - it's the NHS that requires it and I suspect it's they rather than the GP who are doing the pinging. There are a lot of issues with it, not the least is that the URL goes to a site (of which I'd never heard) and includes a code that goes straight to a page which greets me by name.
Yes, that old, crusty, noob security hole. I've no idea how sparse the code space might be but it looks likely that a bit of experimentation with variations would pull up someone else's details - what details there might be I don't know because I haven't pursued beyond the greeting page for my own code let alone trying anyone else's.
I'd have hoped that these days the work experience child responsible - surely nobody more experienced would have done this - would have been quietly advised by an intern to have another go and do better, but no, it's released for use. Perhaps there's scope for a bit of investigative journalism here. Hint.