We try to find critical user details by combining API info leakage, bad encoding and broken access control from the web API of the application.