You must log in or register to comment.
But they are using a loophole to gain sensitive data. They did not gain unauthorised access to the system.
They absolutely gained unauthorized access to the data. Their access was not intended or sanctioned. If it was intended to be public and accessible like it was, this wouldn’t be a story and they wouldn’t have locked down the access.
But by the guy’s definition, they also used a loophole to extract sensitive information, so it it also an exploit.