CVE-2026-107830 PUBLISHED

Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint

Assigner: VulnCheck
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 08.10.2026

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor banq
Product jivejdon
Versions Default: unaffected
  • affected from e03060885db5726e46d30f55ac67920318d0d1fc to ee67a65e65228644a71c8317d7e34deea50f95ef (incl.)

Credits

  • Ikram-4 finder

References

Problem Types

  • Improper Control of Interaction Frequency CWE