OTP reflecting in response sensitive data exposure leads to account take over

Disclosed: 2022-03-26 18:00:23 By rupachandransangothi To upchieve
Critical
Vulnerability Details
## Summary: Sensitive data that is otp is reflecting in the response of phone number otp verification in https://app.upchieve.org ## Steps To Reproduce: 1. Signin with a account 2.After signin it will ask for phone number for otp verification. 3.Capture the request using burpsuite and see the response 4.Now otp is exposing in the response. 5.Account take over is happening. ## Impact Any attacker can login into user account with his/her otp verification which is a high impact of this website.sensitive data is exposing here
Actions
View on HackerOne
Report Stats
  • Report ID: 1318087
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 3
Share this report