Project

General

Profile

Actions

SQA #3372

open

[SQA] Testing on API Critical Security Vulnerabilities Identified - OTP Abuse, Account Takeover, and Data Exposure

Added by Aman Bhuiyan 6 months ago. Updated 6 months ago.

Status:
Complete
Priority:
High
Assignee:
Target version:
Start date:
10/06/2025
Due date:
% Done:

100%

Estimated time:
15:00 h
Spent time:

Description

Summary

  • OTP API Abuse: Missing rate limit allows for denial of service and account enumeration.
  • Account Takeover: The password change endpoint vulnerable to unauthorized password resets.
  • Data Exposure: Sensitive user data (personal, financial) exposed via account history endpoint.
  • Severity: All vulnerabilities are classified as critical, requiring immediate attention.

Pentest

Actions

Also available in: Atom PDF