We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit this vulnerability by manipulating API request URL/payload. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.
Reserved 2025-03-13 | Published 2025-03-13 | Updated 2025-03-13 | Assigner CERT-InCWE-288: Authentication Bypass Using an Alternate Path or Channel
This vulnerability is reported by Mohit Gadiya.
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2025-0048
Support options