email-validation

1 article
sort: new top best
clear filter
0 7/10

A researcher discovered an account takeover vulnerability in a login-with-OTP system by exploiting loose coupling between email and OTP validation. By changing the email parameter in the /login/signin POST request to a victim's email while using a valid OTP sent to the attacker's email, they could gain unauthorized access to any user account.

Avanish Pathak
avanishpathak46.medium.com · kh4sh3i/bug-bounty-writeups · 20 hours ago · details