- Status Closed
-
Assigned To
cbay - Private
Attached to Project: Security vulnerabilities
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026
FS#516 - No Rate Limit on /support/add/ — Support Ticket Spam (CVSS 3.7 Low)
## Summary
POST /support/add/ (authenticated) has no rate limiting. Any user can create unlimited support tickets in rapid succession, flooding alwaysdata's support team inbox.
Severity: Low (CVSS 3.7) | CWE-307
CVSS: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
## Reproduce
1. Log in with any free account
2. Fire 20 rapid POSTs to /support/add/ with subject/message fields
3. All 20 return HTTP 200 — no 429 triggered
## Impact
- Staff inbox flooding via ticket spam
- Can bury legitimate support requests
- Degrades quality of service for legitimate customers
## Remediation
Limit: 5-10 tickets/hour per user account.
Researcher: adityahadipratama4@gmail.com
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
There is a rate limit, and even if there weren't, it's not a vulnerability anyway.
Kind regards,
Cyril