Skip to content

Unauthorized Access fro Modification of User Details via Account Number #2

@Lohithsurya

Description

@Lohithsurya

If a user knows the account number, they are able to change the personal details of the account holder without any further authentication or authorization. This poses a security risk as anyone with the account number can modify sensitive information.

Expected Behavior:
Modifying account details should require proper authentication, such as a password .
Simply knowing the account number should not allow changes to personal information.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions