Rate Limiting Vulnerability in Jivejdon SMS Endpoint by Banq
CVE-2026-107830
6.9MEDIUM
What is CVE-2026-107830?
The Jivejdon application lacks crucial rate limiting on the unauthenticated /account/smsVRAction endpoint in the SmsQQAction class, which exposes it to abuse. This vulnerability allows malicious actors to exploit the system by sending an unlimited number of SMS messages to any phone number, leading to harassment and potential financial loss for the operators by exhausting their Tencent Cloud SMS balance. Attackers can manipulate the newAccount.jsp page to set session attributes, enabling repeated unauthorized requests to the SMS endpoint without restrictions.
Affected Version(s)
jivejdon e03060885db5726e46d30f55ac67920318d0d1fc
