The Everus.org Android application version1.0.7 has a fundamental design flaw where the client can send a random phone number during the second factor flow and the server will update the number on file. Continue reading...