Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by saitan_op - 10.07.2025
Last edited by cbay - 11.07.2025

FS#194 - Rate Limiting Missing on Critical Endpoint – Financial and Availability Risk

The password reset endpoint on admin.alwaysdata.com lacks rate limiting, allowing an attacker to flood a user’s inbox with hundreds or thousands of password reset emails in a short time.

I was able to generate 500+ emails within 30 minutes using Burp Community Edition. An attacker using Burp Pro or custom tools could easily escalate this to thousands of emails in seconds, causing email service abuse, financial impact, and potential denial of service for legitimate users.

This vulnerability could damage the company’s reputation, lead to increased email costs, and affect email delivery reliability for all users.

PoC and screenshot included in the attached PDF report.

Closed by  cbay
11.07.2025 06:57
Reason for closing:  Invalid
Admin
cbay commented on 11.07.2025 06:57

Hello,

causing email service abuse, financial impact, and potential denial of service for legitimate users.

None of those have been demonstrated by your report.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing