OTP reflecting in response sensitive data exposure leads to account take over
Critical
U
UPchieve
Submitted None
Actions:
Reported by
rupachandransangothi
Vulnerability Details
Technical details and impact analysis
## Summary:
Sensitive data that is otp is reflecting in the response of phone number otp verification in https://app.upchieve.org
## Steps To Reproduce:
1. Signin with a account
2.After signin it will ask for phone number for otp verification.
3.Capture the request using burpsuite and see the response
4.Now otp is exposing in the response.
5.Account take over is happening.
## Impact
Any attacker can login into user account with his/her otp verification which is a high impact of this website.sensitive data is exposing here
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable