India - OTP bypass on Phone number verification for account creation
Medium
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
dekster discovered a mobile number verification bypass via incorrect client side validation allowing an attacker to validate a new account creation without a valid phone number attached. @dekster — thank you for reporting this vulnerability and for confirming the resolution.
Actions:
Reported by
deksterh11
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic