Loading HuntDB...

India - OTP bypass on Phone number verification for account creation

Medium
S
Starbucks
Submitted None

Team Summary

Official summary from Starbucks

dekster discovered a mobile number verification bypass via incorrect client side validation allowing an attacker to validate a new account creation without a valid phone number attached. @dekster — thank you for reporting this vulnerability and for confirming the resolution.

Reported by deksterh11

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authentication - Generic