Two-factor authentication (via SMS)
Unknown
Vulnerability Details
Hello Coinbase Security Team
I just found a problem in Two-factor authentication mechanism, here is the details and how to reproduce this issue:
I have two accounts with two emails on `coinbase.com` i active `2FA` on the both of two emails with this phone number `+201066462288`.
From `Chrome` i will try to login using my first email `[email protected]` and now i recieved my code related to this email here `6020930`.
From `FireFox` i will try to do the same thing using my second email `[email protected]` and now i recieved my second code for the second email `1091566`.
Logically, the following steps must be excuted to make the two accounts be logged in:
`[email protected]` => `6020930`
`[email protected]` => `1091566`
But the problem is when i change the two code and emails to be
`[email protected]` => `1091566`
`[email protected]` => `6020930`
I found myself be logged in with two accounts and there is no problem there, The exactly problem is you allow accounts that have the same number to be logged in with each other verification code if they request a login via SMS.
Thank you.
Diaa
Actions
View on HackerOneReport Stats
- Report ID: 66223
- State: Closed
- Substate: informative
- Upvotes: 2