Abusing Virtual number functionality on directapply.indeed.com to get free virtual number

Disclosed by
game0v3r
  • Engagement Indeed
  • Disclosed date 6 months ago
  • Reward $1,000
  • Priority P3 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by game0v3r

I was able to exploit the virtual number functionality on directapply.indeed.com to obtain free virtual numbers. By taking advantage of this vulnerability, I have been able to generate and use virtual numbers without proper authorization, bypassing standard procedures.

Activity