CVE-2026-107830: Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint

Published Oct 8, 2026
·
Updated

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.

Affected Software

1 affected component
Jivejdon Jivejdon>=e0306088<=ee67a65e

Event History

Oct 8, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

No authentication or user interaction is required. An attacker can first load newAccount.jsp to establish the needed session attributes, then repeatedly invoke /account/smsVRAction.

2

Who is exposed to abuse?

Deployments running Jivejdon from commit e0306088 through commit ee67a65e are affected. The endpoint can be used to send SMS messages to arbitrary phone numbers, exposing both recipients to harassment and the operator to Tencent Cloud SMS balance exhaustion.

3

Is the affected endpoint exposed by default?

The data identifies /account/smsVRAction as an unauthenticated endpoint, but does not state whether it is reachable in every default deployment. Exposure depends on whether the application's account registration functionality is reachable to untrusted network users.

4

How can I check for attempted exploitation?

Review application and web access logs for repeated requests to /account/smsVRAction, particularly when preceded by requests for newAccount.jsp. Also investigate unexpected Tencent Cloud SMS usage or SMS sends to numerous or repeatedly targeted phone numbers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203