In-app reader
While creating a test account on the target, I used a phone number from a service called "receive-smss" because the platform doesn't support phone numbers from my country. After entering the OTP, the platform displayed a username along with a "Get OTP on your email" prompt. The email address was masked, showing only the first letter and the domain extension but in this specific case, it was easily guessable for me. I checked the program scope, and it explicitly lists "Username/email enumeration" under out-of-scope issues. Since I haven't found a valid bug yet and this is the first time I've stumbled upon something like this, I'm really unsure and worried about whether I should report it or not. submitted by /u/Bilal351 [link] [comments]
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.