Loading HuntDB...

OTP reflecting in response sensitive data exposure leads to account take over

Critical
U
UPchieve
Submitted None

Vulnerability Details

Technical details and impact analysis

## Summary: Sensitive data that is otp is reflecting in the response of phone number otp verification in https://app.upchieve.org ## Steps To Reproduce: 1. Signin with a account 2.After signin it will ask for phone number for otp verification. 3.Capture the request using burpsuite and see the response 4.Now otp is exposing in the response. 5.Account take over is happening. ## Impact Any attacker can login into user account with his/her otp verification which is a high impact of this website.sensitive data is exposing here

Report Details

Additional information and metadata

State

Closed

Substate

Not-Applicable

Submitted