All Projects

ID Status Summary Opened by
 517 Closed 500 ISE via Host Header @ Injection on /password/lost/  ...adit616 Task Description

## Summary

Injecting @ into the Host header (Host: admin.alwaysdata.com@evil.com) triggers an unhandled HTTP 500 Internal Server Error on /password/lost/. Standard Host values work correctly.

Severity: Low (CVSS 3.3) | CWE-20 (Improper Input Validation)
CVSS: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

## Reproduce
Raw TCP/TLS request:

Host: admin.alwaysdata.com@evil.com GET /password/lost/ HTTP/1.1

Response: HTTP/1.1 500 Internal Server Error

Normal Host: admin.alwaysdata.com returns HTTP 200.

## Evidence
- @-injection in Host header triggers 500 ISE
- Clean Host value returns 200 (no issue)
- No data leakage in error response observed

## Impact
Indicates Host header input reaches internal processing (likely URL building for reset links) without sanitization. Low severity as no data leakage or privilege escalation was demonstrated.

## Remediation
Validate Host header against known-good hostname allowlist at nginx/Django level. Reject requests with malformed Host values (@ symbols, newlines, non-hostname chars) with HTTP 400.

Researcher: adityahadipratama4@gmail.com

 516 Closed No Rate Limit on /support/add/ — Support Ticket Spam (C ...adit616 Task Description

## Summary

POST /support/add/ (authenticated) has no rate limiting. Any user can create unlimited support tickets in rapid succession, flooding alwaysdata's support team inbox.

Severity: Low (CVSS 3.7) | CWE-307
CVSS: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

## Reproduce
1. Log in with any free account
2. Fire 20 rapid POSTs to /support/add/ with subject/message fields
3. All 20 return HTTP 200 — no 429 triggered

## Impact
- Staff inbox flooding via ticket spam
- Can bury legitimate support requests
- Degrades quality of service for legitimate customers

## Remediation
Limit: 5-10 tickets/hour per user account.

Researcher: adityahadipratama4@gmail.com

 515 Closed No Rate Limit on /transfer/add/ — Invitation Spam Abuse ...adit616 Task Description

## Summary

POST /transfer/add/ (authenticated) has no rate limiting. Any free-tier user can spam transfer invitations to arbitrary email addresses, abusing alwaysdata's invitation email system for harassment.

Severity: Medium (CVSS 5.3) | CWE-307
CVSS: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

## Reproduce
1. Log in with any free account
2. Fire 30 concurrent POSTs to /transfer/add/ with email=victim@example.com 3. All 30 return HTTP 200 — no throttling triggered

## Evidence
- 30/30 HTTP 200 (parallel, ~1.55s total)
- No 429 even under concurrent load

## Impact
- Spam victim with unlimited alwaysdata-branded transfer invitation emails
- Abuse alwaysdata sending reputation for targeted harassment

## Remediation
Limit: 5-10 invitations/hour per user + 3/day per target email.

Researcher: adityahadipratama4@gmail.com Full PDF report (4 findings) attached via support ticket.

 514 Closed No Rate Limit on /password/lost/ — Email Flooding (CVSS ...adit616 Task Description

## Summary

POST /password/lost/ has no rate limiting. An attacker can flood any user inbox with unlimited reset emails without auth.

Severity: Medium (CVSS 5.3) | CWE-307
CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

## Reproduce

1. Get CSRF: curl -c /tmp/c.txt admin.alwaysdata.com/password/lost/ -o /dev/null
2. Fire 15 POST requests: all return HTTP 200 (no 429)
3. Contrast: /login/ returns 429 at attempt 11

## Evidence
15/15 HTTP 200 with no throttling on /password/lost/
Login endpoint correctly throttles at attempt 11 - infrastructure supports rate limiting

## Impact
- Flood any user inbox with unlimited reset emails (no auth needed)
- Consume alwaysdata mail delivery resources
- Email-harass targeted users via alwaysdata domain

## Remediation
Rate limit: 3-5 req/hour per IP + 3/hour per email. Reuse infra from /login/.

Researcher: adityahadipratama4@gmail.com Full PDF report (4 findings) attached via support ticket.

Showing tasks 1 - 4 of 4 Page 1 of 1

Available keyboard shortcuts

Tasklist

Task Details

Task Editing