logo

How Inadequate Authentication Logic Led to an MFA Bypass and Account Takeover

ID: cfa243ec-ff7c-54f1-a815-479bf183f8c1

STIX ID: report--cfa243ec-ff7c-54f1-a815-479bf183f8c1

Feed Name: HackerOne Blog

Threat Score
70/100

Date Published: 2024-11-21

Date Updated: 2026-06-12

...
...

This report describes an authentication security write-up that documents a critical MFA bypass affecting Drugs.com: the application issued full session cookies before verifying the one-time MFA code, allowing an attacker to delete a client-side cookie (bb_refresh) and proceed as an authenticated user. The post includes reproduction steps, discusses improper session management as the root cause, and provides mitigation guidance and general authentication best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.