CVE-2026-107830mediumCWE-799

CVE-2026-107830: medium-severity vulnerability in banq jivejdon

Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint

Published

10Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9
exploitation probability
—
observed exploitation
nono source reports it
Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
banq · jivejdon