CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107830: jivejdon affected git revisions

CVE-2026-107830. CVSS 3.1 base score 5.3 (GitHub Advisory Database).

Affected technology

jivejdon · e03060885db5726e46d30f55ac67920318d0d1fc through ee67a65e65228644a71c8317d7e34deea50f95ef
banq

Description’s affected range: through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as none; availability impact as low.

Published

CWE
CWE-799
CCR priority
21.2 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · GitHub Advisory Database
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107830.html