Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over accounts by knowing only a registered mobile number. The platform reportedly exposed the one-time password used for login within a decryptable API response, removing the need to intercept SMS messages, phish users, […]

This article has been indexed from Cyber Security News

Read the original article: