- Status Closed
-
Assigned To
cbay - Private
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026
FS#514 - No Rate Limit on /password/lost/ — Email Flooding (CVSS 5.3 Medium, CWE-307)
## Summary
POST /password/lost/ has no rate limiting. An attacker can flood any user inbox with unlimited reset emails without auth.
Severity: Medium (CVSS 5.3) | CWE-307
CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
## Reproduce
1. Get CSRF: curl -c /tmp/c.txt admin.alwaysdata.com/password/lost/ -o /dev/null
2. Fire 15 POST requests: all return HTTP 200 (no 429)
3. Contrast: /login/ returns 429 at attempt 11
## Evidence
15/15 HTTP 200 with no throttling on /password/lost/
Login endpoint correctly throttles at attempt 11 - infrastructure supports rate limiting
## Impact
- Flood any user inbox with unlimited reset emails (no auth needed)
- Consume alwaysdata mail delivery resources
- Email-harass targeted users via alwaysdata domain
## Remediation
Rate limit: 3-5 req/hour per IP + 3/hour per email. Reuse infra from /login/.
Researcher: adityahadipratama4@gmail.com Full PDF report (4 findings) attached via support ticket.
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task