Misconfiguration of Merchant id in jwt header + Weird Debug mode enabling behavior leads to exposed OTP of mobile number.

Disclosed: 2021-01-20 12:16:49 By basant0x01 To kartpay
High
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 1080901
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report