Tata B2B Platform Flaw Lets Attackers Bypass OTP and Take Over Accounts
ID: d9f32d20-87b0-5403-94fa-8b249206d18c
STIX ID: report--d9f32d20-87b0-5403-94fa-8b249206d18c
Feed Name: Cyber Press
Threat Score
Tata Nexarc's B2B platform returned an AES-encrypted API field that client-side JavaScript could decrypt to reveal plaintext login OTPs, allowing an attacker who knows a registered mobile number to potentially complete passwordless authentication and seize accounts with administrative capabilities; the flaw was reported to CERT-In and fixed by removing the otpGeneratedForMobile field.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
