The authentication of the application is fully client side. This means that if someone gets the authentication details of the database or media server, the application can be exploited. This issue will most likely not be fixed in the current state of the application, because server side code is not yet within the scope of the application.