- Status Closed
-
Assigned To
cbay - Private
Opened by waloodi_109 - 12.09.2025
Last edited by cbay - 13.09.2025
FS#212 - Attacker Can Access Webmail.alwaysdata.com without validating account in admin.alwaysdata.com
#Attacker Can Access Webmail.alwaysdata.com without validating account in admin.alwaysdata.com
Hello Team,
I hope you are doing well. I found Attacker Can Access Wemail.alwaysdata.com without validating account in admin.alwaysdata.com.
#Steps to Reproduce:
1.Go to https://www.alwaysdata.com/en/marketplace/ and install any application you want.
2.Fill the form then submit the request.
3.Then go to webmail.alwaysdata.com to put your address and password in which you had submitted in Step 2.
4.You can see that attacker can login in webmail.alwaysdata.com without validating account in admin.alwaysdata.com.
#Impact:
Attacker can use victim email to create an account and then use the address to login in webmail.alwaysdata.com. Attacker send fake emails and phishing email to someone as a behalf of a victim.
Thank You,
Waleed Anwar
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
I think you're mistaken, that doesn't work. Please attach a video if you still believe you're right.
Kind regards,
Cyril
I will send you the video sir
Here is a video
You sign up with sojarog998@ishense.com and login to the webmail with oliva@alwaysdata.net. Not the same address. There's no vulnerability here.
Attacker can create an account in admin.alwaysdata.com as a behalf of a victim, he/she uses oliva address to login to webmail.alwaysdata.com to send fake emails to anyone, send phishing mails and redirect victim mail to yourself server, plz have a look
Thank you,
Waleed Anwar
Attacker can use victim email to create an account from alwaysdata marketplace then fill the form to submit the request, I already told you sir Attacker use address not email address bcz its mentiond in marketplace.
Please have a look on it, its a serious matter for users.
Thank you,
Waleed Anwar
Any update?
Any update sir??
I already told you sir put address(not an email address) and then password in webmail.alwaysdata.com
Thank You,
Waleed Anwar
Any update??
Any Update about this report, It is validated or not?