Skip to content

[CVE-2023-49032] Hijack SMS codes to an arbitrary phone number #816

@piuppi

Description

@piuppi

Hi @coudot , All,

I have found a vulnerability that would allow an attacker to hijack SMS codes to an arbitrary phone number. This could lead to any user's passwords being changed without any notification.
I am worried that if the PoC appears on GitHub it could be exploited; could you please provide me with an e-mail address on which to continue responsible disclosure?

Thank you and Regards

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions