Fix OTP bypass

XMLWordPrintable

    • Type: Task
    • Resolution: Done
    • Priority: Low
    • 3.2.0
    • Affects Version/s: None
    • None

      The OTP verification process is vulnerable, as the server accepts manipulated responses without proper validation of the OTP, allowing bypass of security controls.    

      An attacker can access user accounts or perform privileged actions without proper OTP verification, leading to unauthorized access, data theft, or further attacks.

      Refer to details in Excel sheet attached in original epic.

        1. Otpbypass error.png
          74 kB
          Vishwanath Balkur
        2. OTP bypass sucess.png
          78 kB
          Vishwanath Balkur
        3. screenshot-1.png
          149 kB
          Thumu Gayathri
        4. screenshot-2.png
          147 kB
          Thumu Gayathri
        5. screenshot-3.png
          147 kB
          Thumu Gayathri
        6. screenshot-4.png
          155 kB
          Thumu Gayathri

            Assignee:
            Thumu Gayathri
            Reporter:
            Dr Mithun James
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - 4 hours
                4h
                Remaining:
                Remaining Estimate - 4 hours
                4h
                Logged:
                Time Spent - Not Specified
                Not Specified