CVE-2026-107830
Received Received - Intake

Jivejdon Unauthenticated SMS Flooding Vulnerability

Vulnerability report for CVE-2026-107830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
banq jivejdon e03060885db5726e46d30f55ac67920318d0d1fc

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-799 The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a lack of rate limiting on the unauthenticated /account/smsVRAction endpoint in Jivejdon. Attackers can exploit this by setting session attributes via newAccount.jsp and repeatedly calling the endpoint to send unlimited SMS messages. This can lead to harassment of arbitrary phone numbers and depletion of the operator's Tencent Cloud SMS balance.

Detection Guidance

Check for repeated requests to the /account/smsVRAction endpoint from the same IP addresses. Monitor SMS logs for unusual activity or spikes in SMS volume. Inspect server access logs for patterns of calls to newAccount.jsp followed by /account/smsVRAction.

Impact Analysis

If you are an operator using Tencent Cloud SMS, this vulnerability could allow attackers to send unlimited SMS messages, exhausting your SMS balance and potentially disrupting legitimate services. For end users, it may result in receiving unsolicited SMS messages or harassment.

Mitigation Strategies

Implement rate limiting on the /account/smsVRAction endpoint. Block or restrict access to newAccount.jsp if not required. Update Jivejdon to a version that includes rate limiting for this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart