Get real-time updates on Telegram
CVE-2026-107830: jivejdon affected git revisions
CVE-2026-107830. CVSS 3.1 base score 5.3 (GitHub Advisory Database).
Affected technology
jivejdon · e03060885db5726e46d30f55ac67920318d0d1fc through ee67a65e65228644a71c8317d7e34deea50f95ef
banq
Description’s affected range: through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as none; availability impact as low.
- CWE
- CWE-799
- CCR priority
- 21.2 /100 (P4)
- CVSS 3.1
- 5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · GitHub Advisory Database
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 03:17:07.463462+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107830.html