Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-02-28
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

2FA requirement bypass when inviting team members


Bug reported by Youssef AboHashish was disclosed at February 28, 2026, 8:55 pm   |   Improper Access Control - Generic

The application's requirement for users to enable 2FA before sending team invitations was bypassed by modifying client-side responses. This allowed invitations to be sent without enabling 2FA, defeating the security requirement.