An unauthorized user with nearby (wireless range) can view personal information of the user using the platform.
An unauthorized user with nearby (wireless range) can view login credentials of the user to perform a full account takeover.
A remote attacker can potentially access user data due to injection attacks.
The app allows the users to edit their information in the app.