resolved
Broken Access Control leads to disclosure of transaction history via /v2/rechargeTransactionHistory endpoint
Bug reported by Hafiz Abdulaziz was disclosed at March 2, 2025, 2:56 pm |
The /v2/rechargeTransactionHistory endpoint in the MyMTN NG mobile app was vulnerable to unauthorized access, allowing an attacker to retrieve transaction details of other users, including recharge dates, amounts before and after the transaction, and transaction IDs.
resolved
Admin Dashboard Access Leads to Updating Merchant Info
Bug reported by Clement 'Tino was disclosed at March 2, 2025, 1:53 pm | Improper Access Control - Generic
The hidden registration endpoint allowed an unauthorized user to sign up for the admin portal, granting access to the registered merchant information. The administrative functionalities permitted the modification of merchant financial account details, disabling and deleting of client accounts.