Power Apps Portals lists are created to display data from tables.
These tables are stored within Microsoft Dataverse.
This is due to all lists having table permissions disabled by default.
The vulnerability issue involving the Power Apps portals was first discovered by UpGuard on May 24, 2021.
In August, the Redmond giant released an update to make APIs enabled as private by default.
It also rolled out a tool to help Power Apps users check the security configs of their portals.
Our products provide customers flexibility and privacy features to design scalable solutions that meet a wide variety of needs.
source: www.techworm.net