Most API vulnerabilities are fast, remote, and easy to exploit. Attackers take full advantage of these attributes.
Think of a REST API like a waiter in a restaurant. You (an app) tell the waiter what you want (your request), and the waiter goes to the kitchen (the server) to get it for you. REST is just a set of ...