HackerOne Disclosed Reports - 2026-08-08

0 Replies, 7 Views

Logo
Medium
resolved

Adding phone number to profile By OTP brute forcing


Bug reported by Ganesh Reddy was disclosed at August 8, 2026, 9:11 am   |   Insecure Storage of Sensitive Information

A vulnerability was found that allowed an attacker to add any phone number to a user's profile by brute-forcing the one-time password (OTP) used for phone number verification. The steps involved intercepting the OTP verification request, using a brute-force attack to find the valid OTP, and then replaying the original request with the discovered OTP to complete the phone number addition.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)