Oct 23, 2020 · Their API can log anyone into the Thrillophilia's database by modifying the email address into the cURL request. In response, the cURL returns the access token and all the other sensitive information given by the user at the time of making the account. CNBCTV18.com was able to verify the issue. How serious is the issue?