Rate Limiting Vulnerability in Jivejdon SMS Endpoint by Banq
CVE-2026-107830

6.9MEDIUM

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107830?

The Jivejdon application lacks crucial rate limiting on the unauthenticated /account/smsVRAction endpoint in the SmsQQAction class, which exposes it to abuse. This vulnerability allows malicious actors to exploit the system by sending an unlimited number of SMS messages to any phone number, leading to harassment and potential financial loss for the operators by exhausting their Tencent Cloud SMS balance. Attackers can manipulate the newAccount.jsp page to set session attributes, enabling repeated unauthorized requests to the SMS endpoint without restrictions.

Affected Version(s)

jivejdon e03060885db5726e46d30f55ac67920318d0d1fc

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.